UCF STIG Viewer Logo

The system package management tool must cryptographically verify the authenticity of software packages during installation.


Overview

Finding ID Version Rule ID IA Controls Severity
GEN008800-ESXI5-PNF GEN008800-ESXI5-PNF GEN008800-ESXI5-PNF_rule Low
Description
To prevent the installation of software from unauthorized sources, the system package management tool must use cryptographic algorithms to verify the packages are authentic. Permanent not a finding - Patches are cryptographically signed by Vmware and/or partners and verified by default prior to installation.
STIG Date
VMware ESXi v5 Security Technical Implementation Guide 2013-01-15

Details

Check Text ( C-GEN008800-ESXI5-PNF_chk )
ESXi supports this requirement and cannot be configured to be out of compliance. This is a permanent not a finding.
Fix Text (F-GEN008800-ESXI5-PNF_fix)
This requirement is permanent not a finding. No fix is required.