| Checked | Name | Title |
|---|---|---|
| ☐ | SV-258970r934568_rule | The vCenter STS service must limit the number of maximum concurrent connections permitted. |
| ☐ | SV-258971r934571_rule | The vCenter STS service must be configured to use strong encryption ciphers. |
| ☐ | SV-258972r934574_rule | The vCenter STS service cookies must have secure flag set. |
| ☐ | SV-258973r934577_rule | The vCenter STS service must initiate session logging upon startup. |
| ☐ | SV-258974r934580_rule | The vCenter STS service must produce log records containing sufficient information regarding event details. |
| ☐ | SV-258975r934583_rule | The vCenter STS service logs folder permissions must be set correctly. |
| ☐ | SV-258976r934586_rule | The vCenter STS service must limit privileges for creating or modifying hosted application shared files. |
| ☐ | SV-258977r934589_rule | The vCenter STS service must disable stack tracing. |
| ☐ | SV-258978r934592_rule | The vCenter STS service must be configured to use a specified IP address and port. |
| ☐ | SV-258979r934595_rule | The vCenter STS service must be configured to limit data exposure between applications. |
| ☐ | SV-258980r934598_rule | The vCenter STS service must be configured to fail to a known safe state if system initialization fails. |
| ☐ | SV-258981r934601_rule | The vCenter STS service must set URIEncoding to UTF-8. |
| ☐ | SV-258982r934604_rule | The vCenter STS service "ErrorReportValve showServerInfo" must be set to "false". |
| ☐ | SV-258983r934607_rule | The vCenter STS service must set an inactive timeout for sessions. |
| ☐ | SV-258984r934610_rule | The vCenter STS service must offload log records onto a different system or media from the system being logged. |
| ☐ | SV-258985r934613_rule | The vCenter STS service must limit the amount of time that each Transmission Control Protocol (TCP) connection is kept alive. |
| ☐ | SV-258986r934616_rule | The vCenter STS service must limit the number of times that each Transmission Control Protocol (TCP) connection is kept alive. |
| ☐ | SV-258987r934619_rule | The vCenter STS service must configure the "setCharacterEncodingFilter" filter. |
| ☐ | SV-258988r934622_rule | The vCenter STS service cookies must have "http-only" flag set. |
| ☐ | SV-258989r934625_rule | The vCenter STS service DefaultServlet must be set to "readonly" for "PUT" and "DELETE" commands. |
| ☐ | SV-258990r934628_rule | The vCenter STS service shutdown port must be disabled. |
| ☐ | SV-258991r934631_rule | The vCenter STS service debug parameter must be disabled. |
| ☐ | SV-258992r934634_rule | The vCenter STS service directory listings parameter must be disabled. |
| ☐ | SV-258993r934637_rule | The vCenter STS service must have Autodeploy disabled. |
| ☐ | SV-258994r934640_rule | The vCenter STS service xpoweredBy attribute must be disabled. |
| ☐ | SV-258995r934643_rule | The vCenter STS service example applications must be removed. |
| ☐ | SV-258996r934646_rule | The vCenter STS service default ROOT web application must be removed. |
| ☐ | SV-258997r934649_rule | The vCenter STS service default documentation must be removed. |
| ☐ | SV-258998r934652_rule | The vCenter STS service files must have permissions in an out-of-the-box state. |
| ☐ | SV-258999r934655_rule | The vCenter STS service must disable "ALLOW_BACKSLASH". |
| ☐ | SV-259000r934658_rule | The vCenter STS service must enable "ENFORCE_ENCODING_IN_GET_WRITER". |
| ☐ | SV-259001r934661_rule | The vCenter STS service manager webapp must be removed. |
| ☐ | SV-259002r934664_rule | The vCenter STS service host-manager webapp must be removed. |