It’s that time again! Actually, it’s the first time that I’m aware of that the vSphere hardening guide has been updated between major releases! Please head on over to the Security and Compliance VMware Community and download the beta of the vSphere 5.5 Update 1 Hardening Guide.
This is a beta release of the guide and as such, I would very much appreciate your prompt feedback. Please reply here or in the Community THIS WEEK. I’d like to release this for General Availability next week.
Here are the proposed changes in the guide.
There are 4 new additions to the guide. Please review.
- enable-VGA-Only-Mode: Used for server VM’s that don’t need a graphical console. e.g. Linux web servers, Windows Core, etc.
- disable-non-essential-3D-features: Remove 3D graphic capabilities from VM’s that don’t need them.
- use-unique-roles: A new companion control to use-service-accounts. If you have multiple service accounts then each one should have a unique role with just enough privs to accomplish their task. This is in line with least-priv operations
- change-sso-admin-password: A great catch. When installing Windows vCenter, you’re prompted to change the password of administrator@vsphere.local. When installing the VCSA in a default manner you are not. This control reminds you to go back and do that.
Read the entire article here, VMware vSphere Hardening Guide 5.5 Update 1 Beta Released