UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Lookup Service application files must be verified for their integrity.


Overview

Finding ID Version Rule ID IA Controls Severity
V-256713 VCLU-70-000008 SV-256713r888730_rule Medium
Description
Verifying the Lookup Service application code is unchanged from its shipping state is essential for file validation and nonrepudiation of the Lookup Service. There is no reason the MD5 hash of the RPM original files should be changed after installation, excluding configuration files.
STIG Date
VMware vSphere 7.0 vCenter Appliance Lookup Service Security Technical Implementation Guide 2023-02-21

Details

Check Text ( C-60388r888728_chk )
At the command prompt, run the following command:

# rpm -V vmware-lookupsvc|grep "^..5......"|grep -E "\.war|\.jar|\.sh|\.py"

If there is any output, this is a finding.
Fix Text (F-60331r888729_fix)
Reinstall the vCenter Server Appliance (VCSA) or roll back to a backup. VMware does not support modifying the Lookup Service installation files manually.