DISA VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v2r1

Audit Details

Name: DISA VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v2r1

Updated: 10/22/2024

Authority: DISA STIG

Plugin: Unix

Revision: 1.0

Estimated Item Count: 35

File Details

Filename: DISA_VMware_vSphere_8.0_vCenter_Appliance_Lookup_Service_STIG_v2r1.audit

Size: 74.3 kB

MD5: d90f1ca33aa48a9db459b9ce0647d02c
SHA256: b1aeb7167e1c43808b21c1acd939f9248f25fe80f3dac15e9feac47428f46af8

Audit Items

DescriptionCategories
DISA_VMware_vSphere_8.0_vCenter_Appliance_Lookup_Service_STIG_v2r1.audit from DISA VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v2r1
VCLU-80-000001 The vCenter Lookup service must limit the number of maximum concurrent connections permitted.

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

VCLU-80-000005 The vCenter Lookup service cookies must have secure flag set.

ACCESS CONTROL

VCLU-80-000013 The vCenter Lookup service must initiate session logging upon startup.

AUDIT AND ACCOUNTABILITY

VCLU-80-000014 The vCenter Lookup service must produce log records containing sufficient information regarding event details.

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

VCLU-80-000025 The vCenter Lookup service logs folder permissions must be set correctly.

AUDIT AND ACCOUNTABILITY

VCLU-80-000034 The vCenter Lookup service must limit privileges for creating or modifying hosted application shared files.

CONFIGURATION MANAGEMENT

VCLU-80-000036 The vCenter Lookup service must disable stack tracing.

CONFIGURATION MANAGEMENT

VCLU-80-000037 The vCenter Lookup service must be configured to use a specified IP address and port.

CONFIGURATION MANAGEMENT

VCLU-80-000057 The vCenter Lookup service must be configured to limit data exposure between applications.

SYSTEM AND COMMUNICATIONS PROTECTION

VCLU-80-000062 The vCenter Lookup service must be configured to fail to a known safe state if system initialization fails.

SYSTEM AND COMMUNICATIONS PROTECTION

VCLU-80-000065 The vCenter Lookup service must set URIEncoding to UTF-8.

SYSTEM AND INFORMATION INTEGRITY

VCLU-80-000067 The vCenter Lookup service 'ErrorReportValve showServerInfo' must be set to 'false'.

SYSTEM AND INFORMATION INTEGRITY

VCLU-80-000070 The vCenter Lookup service must set an inactive timeout for sessions.

ACCESS CONTROL

VCLU-80-000081 The vCenter Lookup service must offload log records onto a different system or media from the system being logged.

AUDIT AND ACCOUNTABILITY

VCLU-80-000124 The vCenter Lookup service must enable 'STRICT_SERVLET_COMPLIANCE'.

CONFIGURATION MANAGEMENT

VCLU-80-000125 The vCenter Lookup service must limit the amount of time that each Transmission Control Protocol (TCP) connection is kept alive.

ACCESS CONTROL

VCLU-80-000126 The vCenter Lookup service must limit the number of times that each Transmission Control Protocol (TCP) connection is kept alive.

ACCESS CONTROL

VCLU-80-000127 The vCenter Lookup service must configure the 'setCharacterEncodingFilter' filter.

SYSTEM AND INFORMATION INTEGRITY

VCLU-80-000129 The vCenter Lookup service cookies must have 'http-only' flag set.

ACCESS CONTROL

VCLU-80-000130 The vCenter Lookup service DefaultServlet must be set to 'readonly' for 'PUT' and 'DELETE' commands.

ACCESS CONTROL

VCLU-80-000134 The vCenter Lookup service shutdown port must be disabled.

CONFIGURATION MANAGEMENT

VCLU-80-000136 The vCenter Lookup service debug parameter must be disabled.

CONFIGURATION MANAGEMENT

VCLU-80-000137 The vCenter Lookup service directory listings parameter must be disabled.

CONFIGURATION MANAGEMENT

VCLU-80-000138 The vCenter Lookup service deployXML attribute must be disabled.

CONFIGURATION MANAGEMENT

VCLU-80-000139 The vCenter Lookup service must have Autodeploy disabled.

CONFIGURATION MANAGEMENT

VCLU-80-000140 The vCenter Lookup service xpoweredBy attribute must be disabled.

CONFIGURATION MANAGEMENT

VCLU-80-000141 The vCenter Lookup service example applications must be removed.

CONFIGURATION MANAGEMENT

VCLU-80-000142 The vCenter Lookup service default ROOT web application must be removed.

CONFIGURATION MANAGEMENT

VCLU-80-000143 The vCenter Lookup service default documentation must be removed.

CONFIGURATION MANAGEMENT

VCLU-80-000144 The vCenter Lookup service files must have permissions in an out-of-the-box state.

CONFIGURATION MANAGEMENT

VCLU-80-000151 The vCenter Lookup service must disable 'ALLOW_BACKSLASH'.

CONFIGURATION MANAGEMENT

VCLU-80-000152 The vCenter Lookup service must enable 'ENFORCE_ENCODING_IN_GET_WRITER'.

CONFIGURATION MANAGEMENT

VCLU-80-000154 The vCenter Lookup service manager webapp must be removed.

CONFIGURATION MANAGEMENT

VCLU-80-000155 The vCenter Lookup service host-manager webapp must be removed.

CONFIGURATION MANAGEMENT