UCF STIG Viewer Logo

The system must enable SSL for NFC.


Overview

Finding ID Version Rule ID IA Controls Severity
V-39299 SRG-OS-99999-ESXI5-000143 SV-51115r2_rule Low
Description
NFC (Network File Copy) is used to migrate or clone a VM between two ESXi hosts over the network. By default, SSL is used only for the authentication of the transfer, but SSL must also be enabled on the data transfer. Without this setting VM contents could potentially be sniffed if the management network is not adequately isolated and secured.
STIG Date
VMware ESXi Server 5.0 Security Technical Implementation Guide 2017-01-06

Details

Check Text ( C-46563r2_chk )
NOTE: SSL for NFC is used for copying or migrating VMs between ESXi hosts via vCenter. If the host is a standalone unit (i.e., not managed by a vCenter Server), this check is not applicable.

From the vSphere client select "Administration >> vCenter Server Settings >> Advanced Settings". Verify "config.nfc.useSSL" is set to true.

If "config.nfc.useSSL" is set to false, this is a finding.
Fix Text (F-44278r1_fix)
From the vSphere client select "Administration >> vCenter Server Settings >> Advanced Settings". Set "config.nfc.useSSL = true".