SV-243118r719597_rule
V-243118
SRG-APP-000516
VCTR-67-000063
CAT II
10
From the vSphere Client, go to Administration >> Access Control >> Roles.
Move any accounts not explicitly designated for cryptographic operations, other than Solution Users, to other roles such as "No Cryptography Administrator".
From the vSphere Client, go to Administration >> Access Control >> Roles.
or
From a PowerCLI command prompt while connected to the vCenter server, run the following command:
Get-VIPermission | Where {$_.Role -eq "Admin"} | Select Role,Principal,Entity,Propagate,IsGroup | FT -Auto
If there are any users other than Solution Users with the "Administrator" role that are not explicitly designated for cryptographic operations, this is a finding.
V-243118
False
VCTR-67-000063
From the vSphere Client, go to Administration >> Access Control >> Roles.
or
From a PowerCLI command prompt while connected to the vCenter server, run the following command:
Get-VIPermission | Where {$_.Role -eq "Admin"} | Select Role,Principal,Entity,Propagate,IsGroup | FT -Auto
If there are any users other than Solution Users with the "Administrator" role that are not explicitly designated for cryptographic operations, this is a finding.
M
5399