UCF STIG Viewer Logo

The operating system must enforce password encryption for transmission.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-OS-000074-ESXI5-PNF SRG-OS-000074-ESXI5-PNF SRG-OS-000074-ESXI5-PNF_rule Medium
Description
Passwords need to be protected at all times and encryption is the standard method for protecting passwords during transmission to ensure unauthorized users/processes do not gain access to them. Applicable, but permanent not-a-finding - Lockdown mode (required) limits access via the vpxuser proxy. The proxy's password is 32 (randomly selected) characters, SHA1 encrypted, not configurable, and changed every 30 days "or" sooner when/if a new host is configured/controlled by the vCenter Server. This password is obfuscated on vCenter.
STIG Date
VMware ESXi v5 Security Technical Implementation Guide 2013-01-15

Details

Check Text ( C-SRG-OS-000074-ESXI5-PNF_chk )
ESXi supports this requirement and cannot be configured to be out of compliance. This is a permanent not a finding.
Fix Text (F-SRG-OS-000074-ESXI5-PNF_fix)
This requirement is permanent not a finding. No fix is required.