SV-240723r679682_rule
V-240723
SRG-APP-000315-WSR-000003
VCRP-67-000008
CAT II
10
Navigate to and open /etc/vmware-rhttpproxy/config.xml.
Locate the first <ssl> block and set its content to the following:
<ssl>
<!-- The server private key file -->
<privateKey>/etc/vmware-rhttpproxy/ssl/rui.key</privateKey>
<!-- The server side certificate file -->
<certificate>/etc/vmware-rhttpproxy/ssl/rui.crt</certificate>
<!-- vecs server name. Currently vecs runs on all node types. -->
<vecsServerName>localhost</vecsServerName>
</ssl>
Restart the service for changes to take effect.
# vmon-cli --restart rhttpproxy
At the command prompt, execute the following command:
# xmllint --xpath '/config/ssl' /etc/vmware-rhttpproxy/config.xml
Expected result:
<ssl>
<!-- The server private key file -->
<privateKey>/etc/vmware-rhttpproxy/ssl/rui.key</privateKey>
<!-- The server side certificate file -->
<certificate>/etc/vmware-rhttpproxy/ssl/rui.crt</certificate>
<!-- vecs server name. Currently vecs runs on all node types. -->
<vecsServerName>localhost</vecsServerName>
</ssl>
If the output does not match the expected result, this is a finding.
V-240723
False
VCRP-67-000008
At the command prompt, execute the following command:
# xmllint --xpath '/config/ssl' /etc/vmware-rhttpproxy/config.xml
Expected result:
<ssl>
<!-- The server private key file -->
<privateKey>/etc/vmware-rhttpproxy/ssl/rui.key</privateKey>
<!-- The server side certificate file -->
<certificate>/etc/vmware-rhttpproxy/ssl/rui.crt</certificate>
<!-- vecs server name. Currently vecs runs on all node types. -->
<vecsServerName>localhost</vecsServerName>
</ssl>
If the output does not match the expected result, this is a finding.
M
5330