UCF STIG Viewer Logo

The system must require authentication upon booting into single-user and maintenance modes.


Overview

Finding ID Version Rule ID IA Controls Severity
GEN000020-ESXI5-PNF GEN000020-ESXI5-PNF GEN000020-ESXI5-PNF_rule Medium
Description
If the system does not require valid root authentication before it boots into single-user or maintenance mode, anyone who invokes single-user or maintenance mode is granted privileged access to all files on the system. Permanent not a finding - The ESXi-v5 hypervisor does not have the ability to boot into single user mode. Maintenance mode (which in fact does not cause the machine to enter a different run-level) can be entered at the command line via "vim-cmd hostsvc/maintenance_mode_enter" when logged in as root. The "vim-cmd" assumes that there is no VM activity. Maintenance Mode is also accessible via the vSphere Client/vCenter. As root (or using a different administrator Active Directory account), from the vSphere Client/vCenter, right click the host icon to select the host and select "Enter Maintenance Mode" from the drop down menu, and click "Yes". Note that in all cases, root (or some "other" privileged administrator account is required to perform this function. There are no "traditional", non-privileged user accounts on ESXi.
STIG Date
VMware ESXi v5 Security Technical Implementation Guide 2013-01-15

Details

Check Text ( C-GEN000020-ESXI5-PNF_chk )
ESXi supports this requirement and cannot be configured to be out of compliance. This is a permanent not a finding.
Fix Text (F-GEN000020-ESXI5-PNF_fix)
This requirement is permanent not a finding. No fix is required.