VCENTER-000015 - Expired certificates must be removed from the vCenter Server

Information

If expired certificates are not removed from the vCenter Server, the user can be subject to a MiTM attack, which potentially might enable compromise through impersonation with the user's credentials to the vCenter Server system.

Solution

If a site procedure to ensure the monitoring and removal of expired certificates from the vCenter Server Windows host does not exist, create one. Check the vCenter Server/host for the presence of expired certificates. Remove all expired certificates

See Also

http://iase.disa.mil/stigs/os/virtualization/Pages/index.aspx

Item Details

References: CAT|II, CCI|CCI-000366, Group-ID|V-39553, Rule-ID|SV-51411r1_rule, STIG-ID|VCENTER-000015, Vuln-ID|V-39553

Plugin: VMware

Control ID: 08fa8bc94a0fa175b278c408b1d15de7fe69f1c33946faaf4b5cd1042af77a28