UCF STIG Viewer Logo

The system must enable SSL for NFC.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-OS-99999-ESXI5-000143 SRG-OS-99999-ESXI5-000143 SRG-OS-99999-ESXI5-000143_rule Low
Description
NFC (Network File Copy) is used to migrate or clone a VM between two ESXi hosts over the network. By default, SSL is used only for the authentication of the transfer, but SSL must also be enabled on the data transfer. Without this setting VM contents could potentially be sniffed if the management network is not adequately isolated and secured.
STIG Date
VMware ESXi v5 Security Technical Implementation Guide 2013-01-15

Details

Check Text ( C-SRG-OS-99999-ESXI5-000143_chk )

From the vSphere client select "Administration >> vCenter Server Settings >> Advanced Settings". Verify "config.nfc.useSSL" is set to true.

If "config.nfc.useSSL" is set to false, this is a finding.

Fix Text (F-SRG-OS-99999-ESXI5-000143_fix)
From the vSphere client select "Administration >> vCenter Server Settings >> Advanced Settings". Set "config.nfc.useSSL = true".