VMware

This Question is Possibly Answered

1 "correct" answer available (10 pts) 2 "helpful" answers available (6 pts)
1 2 3 ... 9 Previous Next 122 Replies Last post: Oct 26, 2009 8:52 AM by Texiwill  

ESX_SRRSecure - Script to allow ESX to pass a DISA Security Readiness Review. posted: Sep 12, 2008 12:28 PM

Click to view pmorrison's profile Enthusiast 75 posts since
Oct 27, 2004
Background: taken from the DISA website: http://iase.disa.mil/stigs/index.html
In a DOD facility all systems must pass the Security Technical Implementation Guide (STIGs) for the host operating system. The STIG is the configuration standard for DOD IA and IA-enabled devices/systems.

A Security Checklist http://iase.disa.mil/stigs/checklist/index.html (sometimes referred to as a lockdown guide, hardening guide, or benchmark configuration) is essentially a document that contains instructions or procedures to verify compliance to a baseline level of security.

Security Readiness Review Scripts (SRRs) http://iase.disa.mil/stigs/SRR/index.html test products for STIG compliance. SRR Scripts are available for all operating systems and databases that have STIGs, and web servers using IIS. The SRR scripts are unlicensed tools developed by the Field Security Office (FSO) and the use of these tools on products is completely at the user's own risk.

The problem:
As of this writing there is no “official” VMware ESX STIGbut it has been determined that since the ESX service console is *nix based it must conform to the latest Unix STIG.

The current Unix STIG is located here: http://iase.disa.mil/stigs/stig/unix-stig-v5r1.pdf
The current Unix SRR is located here: http://iase.disa.mil/stigs/SRR/unix.html

When reviewing the results of the SRR, not all open issues are valid as the DISA SRR was written for UNIX, LINUX, and AIX. The ESX’s console operating system is based on the Linux Redhat Enterprise 4.5 version, but only contains a subset of the entire operating system and has been customized with specific functionality for interfacing the ESX kernel.

The solution:
Running the SRR will result in an open findings report. After remediating the open issues the SRR is re-run. The goal is to have as few open issues and to document the remaining items as either false findings or open issues with notes as to when they will be closed (patches from VMware) or why they need to be left open.
An example of an open issue is:
==========PDI=IAVA1115 Result========================
PDI Number: IAVA1115
Finding Category: CAT II
Reference: IAVA 2007-T-0042
Description: Sun JRE Web Start Multiple Remote
Vulnerabilities.
Status: Open – *will be fixed in a patch from VMware due
in June.*
For example:
IAVA1115: IAVA 2007-T-0042 - Sun JRE Web Start Multiple
Remote Vulnerabilities.
Outdated
/usr/lib/vmware/webAccess/java/jre1.5.0_12/bin/java, JAVA version 1.5.0.12
found on esx.philhome.dyndns.org.
Upgrade to JAVA version 1.5.0.13 on esx.philhome.dyndns.org.
=========================================================

An example of a false finding that will remain is:
==========PDI=IAVA0360 Result========================
PDI Number: IAVA0360
Finding Category: CAT I
Reference: IAVA 2003-A-0015
Description: There are multiple vulnerabilities in OpenSSL.
Status: Open – *This is a documented false finding as the
vulnerabilities were fixed but the version number was not updated.*
For example:
IAVA0360: IAVA 2003-A-0015
/usr/bin/openssl version 0.9.7a found on
esx.philhome.dyndns.org 2.4.21-47.0.1.ELvmnix.
==========PDI=IAVA0410 Result========================

The ESX SRR Secure script is a shell script which attempts to remediate all of the issues possible on an ESX 3.x host. Some prerequisites to running this script are as follows:
1. Must be run as root.
2.The host must be in maintenance mode.
3. Before beginning with the SRR its advised to install the LAuS library to increase auditing capabilities within the ESX service console, as by default there is limited auditing taking place within the service console itself. These libraries are located on the VMware ESX CD in the /vmware/RPM/ directory. (Note: It appears that this is installed by default in ESX 3.5 update 1)
4. Make sure that all passwords meet the complexity requirements. 7 characters with at least 1 number, 1 symbol, 1 upper case and 1 lower case. This needs to be done for root and any additional accounts installed manually. (Do not change any accounts created by adding a host to Virtual Center).

Once the system is ready, run the script as root and allow the host to be rebooted. Re-run the Unix SRR and compare the open findings report. Below is an example of the summary section both before and after running ESX SRR Secure:
Before:
CAT I = 3/541, CAT II = 55/541, CAT III = 3/541, CAT IV = 0/541
After:
CAT I = 1/139, CAT II = 9/345, CAT III = 1/57, CAT IV = 0/5

The remaining open issues should be documented and should be sufficient to present to the DISA FSO for approval.

Since this is the first “public” exposure for this script, please consider this an early release and test this in a NON-production environment until verification can be made that it does not break something. Also, please give feedback as we would love to see what the community thinks and are continuing to try and make this process better.

Updated script with some corrections and begin to address ESX STIG findings.
Attachments:
Click to view Texiwill's profile Guru 10,205 posts since
Jan 13, 2004
Hello,

Who made the determination that it must conform to the latest *nix STIG? That would be interesting information. In this case, the STIG may be satisfied but there may still be vulnerabilies as this test is NOT VMware specific.


Best regards,
Edward L. Haletky
VMware Communities User Moderator
====
Author of the book 'VMWare ESX Server in the Enterprise: Planning and Securing Virtualization Servers', Copyright 2008 Pearson Education. CIO Virtualization Blog: http://www.cio.com/blog/index/topic/168354, As well as the Virtualization Wiki at http://www.astroarch.com/wiki/index.php/Virtualization
Click to view Pennguino's profile Enthusiast 30 posts since
Jan 11, 2005

Hey P,

Received this email. Figured I would pass it along.

The Field Security Operations (FSO) has released the ESX Server Security

Technical Implementation Guide (STIG), Version 1 Release 1 and the ESX

Server Checklist, Version 1 Release 1. The requirements of the ESX Server

STIG become effective immediately.

Classification: UNCLASSIFIED

Here is the PDF http://iase.disa.mil/stigs/checklist/esx_server_checklist_v1r1_30_apr_2008.pdf

I have not read it as of yet. Just found it about 15 minutes ago. Came across your website that referred me to this link. Hope it helps. Hopefully we will be able to say that ESX3i is an appliance and get away from the DISA requirements for a bit.

Click to view vmjim's profile Enthusiast 25 posts since
Nov 13, 2004

Does anyone have a suggestion or script on how to comply with the following UNIX STIG requirement?

•3.1.1.1 GEN000140 - Create and Maintain System Baseline

Confirm with the SA that a system baseline (all device files, all sgid and suid files, and system libraries and binaries), to include cryptographic hashes of files in the baseline, has been created and is maintained.

If a system baseline (all device files, all sgid and suid files, and system libraries and binaries), to include cryptographic hashes of files in the baseline, has not been created and is not maintained, then this is a finding.

The posted script was very helpful.

Click to view vmjim's profile Enthusiast 25 posts since
Nov 13, 2004
I expect the solution is a simple script that finds all the requires files and performs an md5 hash. Something like "find / -name ??? -print |openssl dgst -md5 >/tmp/test.txt". This example is close but does not print the file name, only the md5 hash.
Click to view Texiwill's profile Guru 10,205 posts since
Jan 13, 2004
Hello,

There are several tools I know of that will produce this type of baseline. One is the Tripwire code that comes with most Linux distributions. The one from Tripwire.com will also work. The other is TCT (The Coroner' Toolkit) with its follow-on named Sleuthkit (Brian Carrier's replacement for TCT), and the last tool would be Tara Tool a fork of the Tiger tool.

TCT/Sleuthkit will produce MD5s/SHA1 for each file. However, you really want sha1sum instead as md5's are not forensically sound. And forensics is the reason for the baseline.

Once more you will want to ignore all files in /vmfs when doing this as they will definitely change over time. If you use a well known tool you will have less to worry about going forward.


Best regards,
Edward L. Haletky
VMware Communities User Moderator
====
Author of the book 'VMWare ESX Server in the Enterprise: Planning and Securing Virtualization Servers', Copyright 2008 Pearson Education.
CIO Virtualization Blog: http://www.cio.com/blog/index/topic/168354
As well as the Virtualization Wiki at http://www.astroarch.com/wiki/index.php/Virtualization
Click to view perrymans's profile Lurker 4 posts since
Jun 25, 2008

For some reason the links in the Unix STIG for tools no longer go anywhere.

Tripwire is the most common.

FCheck is the easiest to install and configure (only requiring Perl). Just make sure you touch the database file for it, for some reason the install script doesn't do it.

Thanks. Sean.

Click to view dhand's profile Lurker 2 posts since
Jul 2, 2008
To address GEN000140, I use this script:

echo "suid and sgid files" > checksum.txt
find / -type f \( -perm -4000 -o -perm -2000 \) \-exec /usr/bin/sha1sum {} \; >> checksum.txt
echo " /usr/bin files" >> checksum.txt
find /usr/bin -type f -name "*" \-exec /usr/bin/sha1sum {} \; >> checksum.txt
echo " /etc files" >> checksum.txt
find /etc -type f -name "*" \-exec /usr/bin/sha1sum {} \; >> checksum.txt

Add in any other directories you would also like to save...

Compare the results with a previously saved version, for example

  1. mv checksum.txt checksum.2008_0703
  2. diff checksum.2008_0703 checksum.2008_0624

The checksum files should also be saved wherever the IAO stores all system baselines (some other machine).
Click to view perrymans's profile Lurker 4 posts since
Jun 25, 2008

We also wrote our own fix scripts, but this one is far better scripting. We did have a few more extras which drops our Open Findings from 63 to 18.

Take away the 1 from our development 'Changeme' password, 2 NA'ed for at (not installed on ESX), and 8 NA'ed for no auditd in 2.4 kernel, I get only a couple of busniess cases left to write.

GEN006600 does still fail on us though, so maybe someone can point out where the script is going wrong. We haven't looked into it yet, but think it may be because sendmail isn't there to trigger these logs.

Thanks for the great script! Wish I had it 1.5 months ago when we started our architecture review!

Thanks. Sean.

Attachments:
Click to view green lantern's profile Lurker 1 posts since
Aug 7, 2008

You may not need to do anything special.

TCS Security Blanket will lock down your system. But to get a baseline, you can build a system with jumpstart, and include scripts for configuration. This way every system you jumpstart should have the same thing. Then to ensure your system is not tampered with integrity checkers like tripwire, BART (native for Solaris), or swatch (simple watchdog, its tripwire like).

I think if you had a good jumpstart environment, you should be fine.

Click to view Aaron Lineberger's profile Novice 6 posts since
Aug 8, 2008

I was able to run the latest v1.3 script after an initial install of ESX but now am unable to log in as root on the console after the reboot. I'm wondering if some of the password complexity changes have caused this. has anyone else run into this issue, and does anyone know of a way to get back into the ESX Linux OS without reinstalling the ESX server?

Thanks in advance!

1 2 3 ... 9 Previous Next Go to original post

VMware Developer

SDKs, APIs, Videos, Learn and much more in the Developer community.

Learn More

Developer Sample Code

Increase your developer productivity with VMware API sample code.

Learn More

VMworld Sessions & Labs

Online access to the latest VMworld Sessions & Labs and online services.

Learn more

Purchase PSO Credits Online

Purchase credits to redeem training and consulting services online.

Buy Now

Community Hardware Software

View reported configurations or report your own.

Learn More

VMware vSphere

Come witness the next giant leap in virtualization.

Register Today

Communities