SV-216882r612237_rule
V-216882
SRG-APP-000516
VCWN-65-000063
CAT II
10
From the vSphere Web Client go to Administration >> Access Control >> Roles
Move any accounts not explicitly designated for cryptographic operations, other than Solution Users, to other roles such as "No Cryptography Administrator".
From the vSphere Web Client go to Administration >> Access Control >> Roles
or
From a PowerCLI command prompt while connected to the vCenter server run the following command:
Get-VIPermission | Where {$_.Role -eq "Admin"} | Select Role,Principal,Entity,Propagate,IsGroup | FT -Auto
If there are any users other than Solution Users with the "Administrator" role that are not explicitly designated for cryptographic operations, this is a finding.
V-216882
False
VCWN-65-000063
From the vSphere Web Client go to Administration >> Access Control >> Roles
or
From a PowerCLI command prompt while connected to the vCenter server run the following command:
Get-VIPermission | Where {$_.Role -eq "Admin"} | Select Role,Principal,Entity,Propagate,IsGroup | FT -Auto
If there are any users other than Solution Users with the "Administrator" role that are not explicitly designated for cryptographic operations, this is a finding.
M
4030