Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-239409 | VCPF-67-000008 | SV-239409r674950_rule | Medium |
Description |
---|
Verifying that the Security Token Service application code is unchanged from its shipping state is essential for file validation and nonrepudiation of Performance Charts. There is no reason that the MD5 hash of the rpm original files should be changed after installation, excluding configuration files. |
STIG | Date |
---|---|
VMware vSphere 6.7 Perfcharts Tomcat Security Technical Implementation Guide | 2022-01-03 |
Check Text ( C-42642r674948_chk ) |
---|
At the command prompt, execute the following command: # rpm -V VMware-perfcharts|grep "^..5......"|grep "/usr/lib"|grep -v -E "\.properties|\.conf|\.xml" If any files are returned, this is a finding. |
Fix Text (F-42601r674949_fix) |
---|
Reinstall the VCSA or roll back to a snapshot. Modifying the Performance Charts installation files manually is not supported by VMware. |