Performance Charts application files must be verified for their integrity.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-256618VCPF-70-000008SV-256618r888345_ruleCCI-001749medium
Description
Verifying the Security Token Service application code is unchanged from its shipping state is essential for file validation and nonrepudiation of Performance Charts. There is no reason the MD5 hash of the RPM original files should be changed after installation, excluding configuration files.
STIGDate
VMware vSphere 7.0 vCenter Appliance Perfcharts Security Technical Implementation Guide2023-02-21

Related Frameworks

2 paths across 2 frameworks
NIST 800-531 mapping
  • DISA · V1R1 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI1 mapping
CCI-001749
1.00
  • DISA · V1R1 · disa_xccdf · related

Details

Check Text (C-256618r888345_chk)

At the command prompt, run the following command: # rpm -V VMware-perfcharts|grep "^..5......"|grep -v -E "\.properties|\.conf|\.xml|\.password" If any files are returned, this is a finding.

Fix Text (F-60236r888344_fix)

Reinstall the vCenter Server Appliance (VCSA) or roll back to a backup. VMware does not support modifying the Performance Charts installation files manually.