Check: GEN008050
VMware ESX 3 Server:
GEN008050
(in version v1 r2)
Title
If the system is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords. (Cat II impact)
Discussion
The authentication of automated LDAP connections between systems must not use passwords since more secure methods are available, such as PKI and Kerberos. Additionally, the storage of unencrypted passwords on the system is not permitted.
Check Content
Consult vendor documentation for the procedures concerning the configuration of LDAP for providing authentication and account information. Examine the LDAP configuration file(s). If the LDAP configuration file contains an unencrypted password, this is a finding. If the LDAP configuration file contains an encrypted password accessible by regular users on the system, this is a finding.
Fix Text
Consult vendor documentation for the procedures for configuring LDAP for authentication and account information. Remove any passwords from LDAP configuration files.
Additional Identifiers
Rule ID: SV-30059r1_rule
Vulnerability ID: V-24384
Group Title: GEN008050
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000196 |
The information system, for password-based authentication, stores only cryptographically-protected passwords. |
Controls
Number | Title |
---|---|
IA-5 (1) |
Password-Based Authentication |