VMware Cloud Community
mikefoley
VMware Employee
VMware Employee

vSphere 5.5 Update 1 Hardening Guide beta release - Please comment

Hi,

Attached is the beta release of the vSphere 5.5 Update 1 Hardening Guide.

There are 4 new additions to the guide. Please review.

1. enable-VGA-Only-Mode: Used for server VM's that don't need a graphical console. e.g. Linux web servers, Windows Core, etc.

2. disable-non-essential-3D-features: Remove 3D graphic capabilities from VM's that don't need them

3. use-unique-roles: A new companion control to use-service-accounts. If you have multiple service accounts then each one should have a unique role with just enough privs to accomplish their task. This is in line with least-priv operations

4. change-sso-admin-password: A great catch. When installing Windows vCenter, you're prompted to change the password of administrator@vsphere.local. When installing the VCSA in a default manner you are not. This control reminds you to go back and do that.

The rest are formatting, spelling, clarification, etc..

I had considered removing "disable-datastore-browser" and "disable-mob". I'm holding off at the moment on those. I think they add more trouble than they protect. Feedback on these two would be GREATLY appreciated.

Your feedback is key. I really do listen! Smiley Happy

The intent is for this to GA in one week. The GA of the hardening guide will be reflected in the latest updates from the VCM team as well.

mike

mike

23 Replies
mikefoley
VMware Employee
VMware Employee

Yup, seen it and totally get the need and wish we had something just like that.

However, I'm looking for something that helps me generate the content that something like that could consume. I've looked at a ton of "solutions" and nothing seems to meet the requirements without significant coding/customization. Things I just don't have the cycles for, unfortunately, primarily because creating the content is taking so much bloody time.

mike

mike

0 Kudos
Tsjo
Enthusiast
Enthusiast

WM!H58 is 1.2.3 instead of 1,2,3

ESXi!X19 should be http://pubs.vmware.com/vsphere-55/index.jsp?topic=%2Fcom.vmware.vsphere.install.doc%2FGUID-9F67DB52-...?

ESXi!J26 "Edit the "password requisite /lib/security/$ISA/pam_passwdqc.so retry=N min=N0,N1,N2,N3,N4" entry in the /etc./pam.d/passwd file as outlined in the vSphere Security Guide, "Users and Permissions" chapter.", ESXi already enforces requirements for user passwords. Perhaps change the text to "Edit the "password requisite /lib/security/$ISA/pam_passwdqc.so retry=N min=N0,N1,N2,N3,N4" entry in the /etc./pam.d/passwd file in accordance with industry-standards and internal guidelines or verify the expected settings outlined in the vSphere Security Guide, "Users and Permissions" chapter.

vCenterServer!G22 any reference available?

On the VM sheet guidelines abour "Installation of VMware Tools" and "Enable NTP for VM", either by using VMware Tools synch or (if a Linux VM) a NTP client would be nice.

If you find this information useful, please award points for "correct" or "helpful".
0 Kudos
mariomendez
Contributor
Contributor

Really good work with graphics features and excelent documents. I ask, When Floppy disk will be remove? I work with VMware enviroment since 2011 and i have never used it. :smileyconfused:

0 Kudos
Texiwill
Leadership
Leadership

Hello,

There is a rule to disable floppy devices already and many other connectable devices. Whether you remove it from your Guest OS, there are rules to disable mounting by anyone but an administrator. It is still useful as a password recovery disk in smaller environments. I would not use that approach in big environments, but use a proper password management system.

Best regards,
Edward L. Haletky
VMware Communities User Moderator, VMware vExpert 2009, 2010, 2011,2012,2013,2014

Author of the books 'VMWare ESX and ESXi in the Enterprise: Planning Deployment Virtualization Servers', Copyright 2011 Pearson Education. 'VMware vSphere and Virtual Infrastructure Security: Securing the Virtual Environment', Copyright 2009 Pearson Education.

Virtualization and Cloud Security Analyst: The Virtualization Practice, LLC -- vSphere Upgrade Saga -- Virtualization Security Round Table Podcast

--
Edward L. Haletky
vExpert XIV: 2009-2023,
VMTN Community Moderator
vSphere Upgrade Saga: https://www.astroarch.com/blogs
GitHub Repo: https://github.com/Texiwill
0 Kudos