vSphere Client must be configured to enable SSL/TLS.
DISA Rule
SV-239748r679471_rule
Vulnerability Number
V-239748
Group Title
SRG-APP-000015-WSR-000014
Rule Version
VCFL-67-000006
Severity
CAT I
CCI(s)
- CCI-000197 - The information system, for password-based authentication, transmits only cryptographically-protected passwords.
- CCI-000803 - The information system implements mechanisms for authentication to a cryptographic module that meet the requirements of applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance for such authentication.
- CCI-001453 - The information system implements cryptographic mechanisms to protect the integrity of remote access sessions.
- CCI-002314 - The information system controls remote access methods.
- CCI-002418 - The information system protects the confidentiality and/or integrity of transmitted information.
- CCI-002422 - The information system maintains the confidentiality and/or integrity of information during reception.
Weight
10
Fix Recommendation
Navigate to and open /usr/lib/vmware-vsphere-client/server/configuration/tomcat-server.xml.
Ensure that the <Connector> node with 'port=9443' contains the following value:
SSLEnabled="true"
Check Contents
At the command prompt, execute the following command:
# xmllint --format --xpath '/Server/Service/Connector[@port=9443]/@SSLEnabled' /usr/lib/vmware-vsphere-client/server/configuration/tomcat-server.xml
Expected result:
SSLEnabled="true"
If the output does not match the expected result, this is a finding.
Vulnerability Number
V-239748
Documentable
False
Rule Version
VCFL-67-000006
Severity Override Guidance
At the command prompt, execute the following command:
# xmllint --format --xpath '/Server/Service/Connector[@port=9443]/@SSLEnabled' /usr/lib/vmware-vsphere-client/server/configuration/tomcat-server.xml
Expected result:
SSLEnabled="true"
If the output does not match the expected result, this is a finding.
Check Content Reference
M
Target Key
5336
Comments