Hash signatures for the /etc files are not reviewed monthly.


Finding ID Version Rule ID IA Controls Severity
V-15833 ESX0380 SV-16772r1_rule Medium
Several files within ESX Server should be checked for file system integrity periodically. These files have been deemed critical by VMware in maintaining file system integrity. System administrators must ensure these files have the correct permissions and have not been modified. To ensure integrity, system administrators will use a FIPS 140-2 hash algorithm to create signatures of these files and store them offline. Comparing these hash values periodically will verify the integrity of the files.
VMware ESX 3 Policy 2016-05-03


Check Text ( C-16181r1_chk )
Ask the IAO/SA how often the hash signatures are reviewed. If they are not reviewed at least monthly, this is a finding.

File Location Permission
/etc/fstab 640
/etc/group 644
/etc/host.conf 640
/etc/hosts 640
/etc/hosts.allow 640
/etc/hosts.deny 640
/etc/logrotate.conf 640
/etc/logrotate.d/ 700
/etc/modules.conf 640
/etc/motd 640
/etc/ntp 755
/etc/ntp.conf 644
/etc/pam.d/system-auth 644
/etc/profile 644
/etc/shadow 400
/etc/securetty 600
/etc/ssh/sshd_config 600
/etc/snmp 755
/etc/sudoers 440
/etc/vmware 755
Fix Text (F-15784r1_fix)
Review the hash signatures for the /etc files monthly.