Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-OS-000067-ESXI5-PF | SRG-OS-000067-ESXI5-PF | SRG-OS-000067-ESXI5-PF_rule | Medium |
Description |
---|
The cornerstone of the PKI is the private key used to encrypt or digitally sign information. If the private key is stolen, this will lead to the compromise of the authentication and non-repudiation gained through PKI because the attacker can use the private key to digitally sign documents and can pretend to be the authorized user. Both the holders of a digital certificate and the issuing authority must protect the computers, storage devices or whatever they use to keep the private keys. Permanent finding - This function is not implemented for a hypervisor. |
STIG | Date |
---|---|
VMware ESXi v5 Security Technical Implementation Guide | 2013-01-15 |
Check Text ( C-SRG-OS-000067-ESXI5-PF_chk ) |
---|
ESXi does not support this requirement. This is a permanent finding. |
Fix Text (F-SRG-OS-000067-ESXI5-PF_fix) |
---|
This requirement is a permanent finding and cannot be fixed. An appropriate mitigation for the system must be implemented but this finding cannot be considered fixed. |