SV-207673r388482_rule
V-207673
SRG-OS-000480-VMM-002000
ESXI-65-000076
CAT II
10
Temporarily enable SSH, connect to the ESXi host and run the following command:
/usr/lib/vmware/secureboot/bin/secureBoot.py -c
If the output indicates that Secure Boot cannot be enabled, correct the discrepancies and try again. If the discrepancies cannot be rectified this finding is downgraded to a CAT III.
Consult your vendor documentation and boot the host into BIOS setup mode. Enable UEFI boot mode and Secure Boot. Restart the host.
Temporarily enable SSH, connect to the ESXi host and run the following command to verify that Secure Boot is enabled:
/usr/lib/vmware/secureboot/bin/secureBoot.py -s
Temporarily enable SSH, connect to the ESXi host and run the following command:
/usr/lib/vmware/secureboot/bin/secureBoot.py -s
If the output is not Enabled, this is a finding.
V-207673
False
ESXI-65-000076
Temporarily enable SSH, connect to the ESXi host and run the following command:
/usr/lib/vmware/secureboot/bin/secureBoot.py -s
If the output is not Enabled, this is a finding.
M
2925