STIGQter STIGQter: STIG Summary:

VMware vSphere 8.0 vCenter Appliance Secure Token Service (STS) Security Technical Implementation Guide

Version: 2

Release: 2 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-258970r960735_ruleThe vCenter STS service must limit the number of maximum concurrent connections permitted.
SV-258972r1137578_ruleThe vCenter STS service cookies must have secure flag set.
SV-258973r960888_ruleThe vCenter STS service must initiate session logging upon startup.
SV-258974r960891_ruleThe vCenter STS service must produce log records containing sufficient information regarding event details.
SV-258975r960930_ruleThe vCenter STS service logs folder permissions must be set correctly.
SV-258976r960960_ruleThe vCenter STS service must limit privileges for creating or modifying hosted application shared files.
SV-258977r960963_ruleThe vCenter STS service must disable stack tracing.
SV-258978r1043177_ruleThe vCenter STS service must be configured to use a specified IP address and port.
SV-258979r1043180_ruleThe vCenter STS service must be configured to limit data exposure between applications.
SV-258980r961122_ruleThe vCenter STS service must be configured to fail to a known safe state if system initialization fails.
SV-258981r961158_ruleThe vCenter STS service must set URIEncoding to UTF-8.
SV-258982r961167_ruleThe vCenter STS service "ErrorReportValve showServerInfo" must be set to "false".
SV-258983r1043182_ruleThe vCenter STS service must set an inactive timeout for sessions.
SV-258984r1210437_ruleThe vCenter STS service must off-load log records onto a different system or media from the system being logged.
SV-258985r960735_ruleThe vCenter STS service must limit the amount of time that each Transmission Control Protocol (TCP) connection is kept alive.
SV-258986r960735_ruleThe vCenter STS service must limit the number of times that each Transmission Control Protocol (TCP) connection is kept alive.
SV-258987r1210439_ruleThe vCenter STS service must configure the "setCharacterEncodingFilter" filter.
SV-258988r1137578_ruleThe vCenter STS service cookies must have "http-only" flag set.
SV-258989r1137578_ruleThe vCenter STS service DefaultServlet must be set to "readonly" for "PUT" and "DELETE" commands.
SV-258990r960963_ruleThe vCenter STS service shutdown port must be disabled.
SV-258991r960963_ruleThe vCenter STS service debug parameter must be disabled.
SV-258992r960963_ruleThe vCenter STS service directory listings parameter must be disabled.
SV-258993r960963_ruleThe vCenter STS service must have Autodeploy disabled.
SV-258994r960963_ruleThe vCenter STS service xpoweredBy attribute must be disabled.
SV-258995r960963_ruleThe vCenter STS service example applications must be removed.
SV-258996r960963_ruleThe vCenter STS service default ROOT web application must be removed.
SV-258997r960963_ruleThe vCenter STS service default documentation must be removed.
SV-258998r961461_ruleThe vCenter STS service files must have permissions in an out-of-the-box state.
SV-258999r961863_ruleThe vCenter STS service must disable "ALLOW_BACKSLASH".
SV-259000r961863_ruleThe vCenter STS service must enable "ENFORCE_ENCODING_IN_GET_WRITER".
SV-259001r960963_ruleThe vCenter STS service manager webapp must be removed.
SV-259002r1003674_ruleThe vCenter STS service host-manager webapp must be removed.
SV-266136r1003677_ruleThe vCenter STS service deployXML attribute must be disabled.