SV-243133r719642_rule
V-243133
SRG-APP-000516
VCTR-67-000078
CAT II
10
From the vSphere Client, go to Administration >> Single Sign-On >> Configuration >> Smart Card Authentication.
Next to "Authentication methods", click "Edit".
Click the "Enable smart card authentication" radio button and click "Save".
To reenable password authentication for troubleshooting purposes, run the following command on the vCenter server:
C:\Program Files\VMware\VCenter server\VMware Identity Services\sso-config.bat -set_authn_policy -pwdAuthn true -winAuthn false -certAuthn false -securIDAuthn false -t vsphere.local
Note: For vCenter Server Appliance, this is not applicable.
From the vSphere Client, go to Administration >> Single Sign-On >> Configuration >> Smart Card Authentication.
If "Smart card authentication" is not enabled and "Password and windows session authentication" is not disabled, this is a finding.
V-243133
False
VCTR-67-000078
Note: For vCenter Server Appliance, this is not applicable.
From the vSphere Client, go to Administration >> Single Sign-On >> Configuration >> Smart Card Authentication.
If "Smart card authentication" is not enabled and "Password and windows session authentication" is not disabled, this is a finding.
M
5399