Access to SSL certificates must be monitored.

From VMware vCenter Server Version 5 Security Technical Implementation Guide

Part of ESXi5-412

Associated with: CCI-000366

SV-51409r1_rule Access to SSL certificates must be monitored.

Vulnerability discussion

The directory that contains the SSL certificates only needs to be accessed by the service account user on a regular basis. Occasionally, the vCenter Server system administrator might need to access it for support purposes. The SSL certificate can be used to impersonate vCenter and decrypt the vCenter database password.

Check content

Ask the SA if event log monitoring is used to alert on non-service account access to the certificates directory. If event log monitoring is not used, this is a finding.

Fix text

Set up Windows event log monitoring to alert on nonservice account access to the certificates directory.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer