1. Home
  2. Security Hardening
  3. DISA STIG VMware vSphere 6.7 ESXi V1R1
  4. ESXI-67-000032 – The ESXi host must prohibit the reuse of passwords within five iterations.

ESXI-67-000032 – The ESXi host must prohibit the reuse of passwords within five iterations.

Details

If a user or root used the same password continuously or was allowed to change it back shortly after being forced to change it to something else, it would provide a potential intruder with the opportunity to keep guessing at one user’s password until it was guessed correctly.

Solution

From the vSphere Client, select the ESXi host and go to Configure >> System >> Advanced System Settings.

Select the ‘Security.PasswordHistory’ value and configure it to ‘5’.

or

From a PowerCLI command prompt while connected to the ESXi host, run the following command:

Get-VMHost | Get-AdvancedSetting -Name Security.PasswordHistory | Set-AdvancedSetting -Value 5

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Identification and Authentication.This control applies to the following type of system VMware.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles