UCF STIG Viewer Logo

The operating system must validate the integrity of security attributes exchanged between systems.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-OS-000178-ESXI5-PNF SRG-OS-000178-ESXI5-PNF SRG-OS-000178-ESXI5-PNF_rule Medium
Description
When data is exchanged between information systems, the security attributes associated with the data needs to be maintained. Security attributes are an abstraction representing the basic properties or characteristics of an entity with respect to safeguarding information; typically associated with internal data structures (e.g., records, buffers, files) within the information system and used to enable the implementation of access control and flow control policies, reflect special dissemination, handling or distribution instructions, or support other aspects of the information security policy. Security attributes may be explicitly or implicitly associated with the information contained within the information system. Applicable, but permanent not-a-finding - All versions of VMware products, including all releases of vCenter Server use X.509 certificates to encrypt session information sent over SSL (secure sockets layer protocol) connections between server and client components such as ESXi-v5. CA certs are also addressed.
STIG Date
VMware ESXi v5 Security Technical Implementation Guide 2013-01-15

Details

Check Text ( C-SRG-OS-000178-ESXI5-PNF_chk )
ESXi supports this requirement and cannot be configured to be out of compliance. This is a permanent not a finding.
Fix Text (F-SRG-OS-000178-ESXI5-PNF_fix)
This requirement is permanent not a finding. No fix is required.