Check: VCUI-67-000026
VMware vSphere 6.7 UI Tomcat STIG:
VCUI-67-000026
(in versions v1 r3 through v1 r1)
Title
vSphere UI must use a logging mechanism that is configured to allocate log record storage capacity large enough to accommodate the logging requirements of the web server. (Cat II impact)
Discussion
To ensure that the logging mechanism used by the web server has sufficient storage capacity in which to write the logs, the logging mechanism needs to be able to allocate log record storage capacity. vSphere UI configures log sizes and rotation appropriately as part of its installation routine. Verifying that the logging configuration file (serviceability.xml) has not been modified is sufficient to determine if the logging configuration has been modified from the default.
Check Content
At the command prompt, execute the following command: # rpm -V vsphere-ui|grep serviceability.xml|grep "^..5......" If the above command returns any output, this is a finding.
Fix Text
Reinstall the VCSA or roll back to a snapshot. Modifying the vSphere UI installation files manually is not supported by VMware.
Additional Identifiers
Rule ID: SV-239707r879730_rule
Vulnerability ID: V-239707
Group Title: SRG-APP-000357-WSR-000150
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001849 |
The organization allocates audit record storage capacity in accordance with organization-defined audit record storage requirements. |
Controls
Number | Title |
---|---|
AU-4 |
Audit Storage Capacity |