Ensure a centralized location is configured to collect ESXi host core dumps Details The VMware vSphere Network Dump Collector service allows for collecting diagnostic information from a host that experiences a critical...
Ensure Active Directory is used for local user authentication Details ESXi can be configured to use a directory service such as Active Directory to manage users and groups. It...
Ensure a non-root user account exists for local admin access Details By default, each ESXi host has a single ‘root’ admin account that is used for local administration and to...
Ensure expired and revoked SSL certificates are removed from the ESXi server Details By default, ESXi hosts do not have Certificate Revocation List (CRL) checking available, so expired and revoked SSL certificates...
Ensure no unauthorized kernel modules are loaded on the host Details ESXi hosts by default do not permit the loading of kernel modules that lack valid digital signatures. This feature...
Ensure the ESXi host firewall is configured to restrict access to services running on the host Details The ESXi firewall is enabled by default and allows ping (ICMP) and communication with DHCP/DNS clients. Access to services...
Ensure the Image Profile VIB acceptance level is configured properly Details A VIB (vSphere Installation Bundle) is a collection of files that are packaged into an archive. The VIB contains...