STIGQter STIGQter: STIG Summary: VMware vRealize Automation 7.x SLES Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Sep 2018:

The SLES for vRealize must store only encrypted representations of passwords.

DISA Rule

SV-100223r1_rule

Vulnerability Number

V-89573

Group Title

SRG-OS-000073-GPOS-00041

Rule Version

VRAU-SL-000365

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Reset the user password using the following command:

# passwd [user account]

Check Contents

Check that the user account passwords are stored hashed using sha512 by running the following command:

# more /etc/shadow

If the password hash does not begins with "$6$" for user accounts such as "root" or "admin", this is a finding.

Vulnerability Number

V-89573

Documentable

False

Rule Version

VRAU-SL-000365

Severity Override Guidance

Check that the user account passwords are stored hashed using sha512 by running the following command:

# more /etc/shadow

If the password hash does not begins with "$6$" for user accounts such as "root" or "admin", this is a finding.

Check Content Reference

M

Target Key

3459

Comments