<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>VMtoday &#187; hardening</title> <atom:link href="http://vmtoday.com/tag/hardening/feed/" rel="self" type="application/rss+xml" /><link>http://vmtoday.com</link> <description>VMware News, Views, &#38; How-To&#039;s from vExpert Josh Townsend</description> <lastBuildDate>Fri, 18 May 2012 19:03:15 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.2</generator> <item><title>Securing Your Virtual Infrastructure</title><link>http://vmtoday.com/2009/01/securing-your-virtual-infrastructure/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=securing-your-virtual-infrastructure</link> <comments>http://vmtoday.com/2009/01/securing-your-virtual-infrastructure/#comments</comments> <pubDate>Tue, 27 Jan 2009 21:03:38 +0000</pubDate> <dc:creator>Joshua Townsend</dc:creator> <category><![CDATA[General IT]]></category> <category><![CDATA[VMware]]></category> <category><![CDATA[VMware How To]]></category> <category><![CDATA[best practices]]></category> <category><![CDATA[ESX]]></category> <category><![CDATA[hardening]]></category> <category><![CDATA[security]]></category> <category><![CDATA[virtual]]></category> <category><![CDATA[virtualization]]></category><guid
isPermaLink="false">http://vmtoday.com/?p=45</guid> <description><![CDATA[Between budget cuts and New Year&#8217;s resolutions, improving your security posture is probably near the top of your to-do list.  Much has been made of security concerns in a virtual environment, but it is always good to re-visit your configurations and make sure they are still on par with recommended best practices.  I began re-reviewing [...]]]></description> <content:encoded><![CDATA[<p></p><p>Between budget cuts and New Year&#8217;s resolutions, improving your security posture is probably near the top of your to-do list.  Much has been made of security concerns in a virtual environment, but it is always good to re-visit your configurations and make sure they are still on par with recommended best practices.  I began re-reviewing VI security best practices after reading at post by Bob Plankers at <a
title="The Lone SysAdmin: Why Would You Want a Second Superuser" href="http://lonesysadmin.net/2008/12/23/why-would-you-want-a-second-superuser/" target="_blank">The Lone SysAdmin</a> (Bob has been on my reading list for years &#8211; he has a great style and always brings fresh insights) on why you would want a second super-user account on your ESX servers.</p><p>We certainly all have our own opinions and operations procedures when it comes to configuring and hardening our environments, but I decided to take a look at what the experts had to say on this particular subject and other basic build and hardening recommendations.  Here is what I found:</p><p><a
title="VMware Security Resources" href="http://www.vmware.com/technology/security/resources.html" target="_blank">VMware Security Resources</a></p><p><a
title="VMware Security Utilities" href="http://www.vmware.com/technology/security/utilities.html" target="_blank">VMware Security Utilities</a></p><p><a
title="VMware Security Hardening Whitepaper" href="http://www.vmware.com/files/pdf/vi35_security_hardening_wp.pdf" target="_blank">VI3.5 Security Hardening Whitepaper</a></p><p><a
title="DISA STIG" href="http://iase.disa.mil/stigs/stig/esx_server_stig_v1r1_final.pdf" target="_blank">Defense Informaion Systems Agency (DISA) ESX Server Security Technical Implementation Guide</a></p><p><a
title="DISA ESX Server Checklist" href="http://iase.disa.mil/stigs/checklist/esx_server_checklist_v1_r1-2_03sep2008pdf.zip" target="_blank">DISA ESX Server Checklist</a></p><p>As a side note, DISA publishes many STIG&#8217;s at <a
title="DISA STIG Library" href="http://iase.disa.mil/stigs/" target="_blank">http://iase.disa.mil/stigs/</a>.  Your tax dollars paid for these, so you might as well check them out.</p><p><a
title="NSA ESX Configuration Guide" href="http://www.nsa.gov/snac/support/I733-009R-2008.pdf" target="_blank">NSA VMware ESX  Server 3 Configuration Guide</a></p><p>There are also numerous tips and scripts for locking down your virtual infrastructure in the VMware Community Forums (Start here: <a
title="ESX_SRRSecure - Script to allow ESX to pass a DISA Security Readiness Review" href="http://communities.vmware.com/message/941372" target="_blank">http://communities.vmware.com/message/941372</a>).</p><p>So back to the question of second super user accounts: It seems that best practices are to create a second user account with sufficient access to the console, granting that user SUDO privledges, and then disabling the default root account.</p> ]]></content:encoded> <wfw:commentRss>http://vmtoday.com/2009/01/securing-your-virtual-infrastructure/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 4/13 queries in 0.024 seconds using disk: basic
Object Caching 470/470 objects using disk: basic
Content Delivery Network via Amazon Web Services: CloudFront: cloudfront.vmtoday.com

Served from: vmtoday.com @ 2012-05-21 19:36:45 -->
