STIGQter STIGQter: STIG Summary: VMW vSphere 6.5 vCenter Server for Windows Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 22 Jan 2021:

The vCenter Server for Windows must disable Password and Windows integrated authentication.

DISA Rule

SV-216880r612237_rule

Vulnerability Number

V-216880

Group Title

SRG-APP-000516

Rule Version

VCWN-65-000061

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

1. Login to the Platform Services Controller web interface with administrator@vsphere.local from

https://<FQDN or IP of PSC>/psc

In an embedded deployment the Platform Services Controller host name or IP address is the same as the vCenter Server host name or IP address.

If you specified a different SSO domain during installation, log in as administrator@<mydomain>.

2. Browse to Single Sign-On >> Configuration.

3. Click the "Smart Card Configuration" tab, click the "Edit" button next to “Authentication Configuration”.

4. Check the box next to “Password and Windows session authentication”. Click "OK".

To re-enable password authentication for troubleshooting run the following command from the PSC:

/opt/vmware/bin/sso-config.sh -set_authn_policy -pwdAuthn true -winAuthn false -certAuthn false -securIDAuthn false -t vsphere.local

Check Contents

1. Login to the Platform Services Controller web interface with administrator@vsphere.local from

https://<FQDN or IP of PSC>/psc

In an embedded deployment the Platform Services Controller host name or IP address is the same as the vCenter Server host name or IP address.

If you specified a different SSO domain during installation, log in as administrator@<mydomain>.

2. Browse to Single Sign-On >> Configuration.

3. Click the "Smart Card Configuration" tab, click the "Edit" button next to “Authentication Configuration”.

If the selection box next to “Password and Windows session authentication” is checked, this is a finding.

Vulnerability Number

V-216880

Documentable

False

Rule Version

VCWN-65-000061

Severity Override Guidance

1. Login to the Platform Services Controller web interface with administrator@vsphere.local from

https://<FQDN or IP of PSC>/psc

In an embedded deployment the Platform Services Controller host name or IP address is the same as the vCenter Server host name or IP address.

If you specified a different SSO domain during installation, log in as administrator@<mydomain>.

2. Browse to Single Sign-On >> Configuration.

3. Click the "Smart Card Configuration" tab, click the "Edit" button next to “Authentication Configuration”.

If the selection box next to “Password and Windows session authentication” is checked, this is a finding.

Check Content Reference

M

Target Key

4030

Comments