<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>VMtoday &#187; hardening</title> <atom:link href="http://vmtoday.com/tag/hardening/feed/" rel="self" type="application/rss+xml" /><link>http://vmtoday.com</link> <description>VMware News, Views, &#38; How-To&#039;s from vExpert Josh Townsend</description> <lastBuildDate>Wed, 08 Feb 2012 20:33:54 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>Securing Your Virtual Infrastructure</title><link>http://vmtoday.com/2009/01/securing-your-virtual-infrastructure/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=securing-your-virtual-infrastructure</link> <comments>http://vmtoday.com/2009/01/securing-your-virtual-infrastructure/#comments</comments> <pubDate>Tue, 27 Jan 2009 21:03:38 +0000</pubDate> <dc:creator>Joshua Townsend</dc:creator> <category><![CDATA[General IT]]></category> <category><![CDATA[VMware]]></category> <category><![CDATA[VMware How To]]></category> <category><![CDATA[best practices]]></category> <category><![CDATA[ESX]]></category> <category><![CDATA[hardening]]></category> <category><![CDATA[security]]></category> <category><![CDATA[virtual]]></category> <category><![CDATA[virtualization]]></category><guid
isPermaLink="false">http://vmtoday.com/?p=45</guid> <description><![CDATA[Between budget cuts and New Year&#8217;s resolutions, improving your security posture is probably near the top of your to-do list.  Much has been made of security concerns in a virtual environment, but it is always good to re-visit your configurations and make sure they are still on par with recommended best practices.  I began re-reviewing [...]]]></description> <content:encoded><![CDATA[<p></p><p>Between budget cuts and New Year&#8217;s resolutions, improving your security posture is probably near the top of your to-do list.  Much has been made of security concerns in a virtual environment, but it is always good to re-visit your configurations and make sure they are still on par with recommended best practices.  I began re-reviewing VI security best practices after reading at post by Bob Plankers at <a
title="The Lone SysAdmin: Why Would You Want a Second Superuser" href="http://lonesysadmin.net/2008/12/23/why-would-you-want-a-second-superuser/" target="_blank">The Lone SysAdmin</a> (Bob has been on my reading list for years &#8211; he has a great style and always brings fresh insights) on why you would want a second super-user account on your ESX servers.</p><p>We certainly all have our own opinions and operations procedures when it comes to configuring and hardening our environments, but I decided to take a look at what the experts had to say on this particular subject and other basic build and hardening recommendations.  Here is what I found:</p><p><a
title="VMware Security Resources" href="http://www.vmware.com/technology/security/resources.html" target="_blank">VMware Security Resources</a></p><p><a
title="VMware Security Utilities" href="http://www.vmware.com/technology/security/utilities.html" target="_blank">VMware Security Utilities</a></p><p><a
title="VMware Security Hardening Whitepaper" href="http://www.vmware.com/files/pdf/vi35_security_hardening_wp.pdf" target="_blank">VI3.5 Security Hardening Whitepaper</a></p><p><a
title="DISA STIG" href="http://iase.disa.mil/stigs/stig/esx_server_stig_v1r1_final.pdf" target="_blank">Defense Informaion Systems Agency (DISA) ESX Server Security Technical Implementation Guide</a></p><p><a
title="DISA ESX Server Checklist" href="http://iase.disa.mil/stigs/checklist/esx_server_checklist_v1_r1-2_03sep2008pdf.zip" target="_blank">DISA ESX Server Checklist</a></p><p>As a side note, DISA publishes many STIG&#8217;s at <a
title="DISA STIG Library" href="http://iase.disa.mil/stigs/" target="_blank">http://iase.disa.mil/stigs/</a>.  Your tax dollars paid for these, so you might as well check them out.</p><p><a
title="NSA ESX Configuration Guide" href="http://www.nsa.gov/snac/support/I733-009R-2008.pdf" target="_blank">NSA VMware ESX  Server 3 Configuration Guide</a></p><p>There are also numerous tips and scripts for locking down your virtual infrastructure in the VMware Community Forums (Start here: <a
title="ESX_SRRSecure - Script to allow ESX to pass a DISA Security Readiness Review" href="http://communities.vmware.com/message/941372" target="_blank">http://communities.vmware.com/message/941372</a>).</p><p>So back to the question of second super user accounts: It seems that best practices are to create a second user account with sufficient access to the console, granting that user SUDO privledges, and then disabling the default root account.</p><div
class="shr-publisher-45"></div><div
style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div
class='shareaholic-like-buttonset' style='float:none;height:30px;'><a
class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fvmtoday.com%2F2009%2F01%2Fsecuring-your-virtual-infrastructure%2F' data-shr_title='Securing+Your+Virtual+Infrastructure'></a><a
class='shareaholic-fbsend' data-shr_href='http%3A%2F%2Fvmtoday.com%2F2009%2F01%2Fsecuring-your-virtual-infrastructure%2F'></a><a
class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fvmtoday.com%2F2009%2F01%2Fsecuring-your-virtual-infrastructure%2F' data-shr_title='Securing+Your+Virtual+Infrastructure'></a></div><div
style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div>]]></content:encoded> <wfw:commentRss>http://vmtoday.com/2009/01/securing-your-virtual-infrastructure/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 4/15 queries in 0.028 seconds using disk: basic
Object Caching 510/518 objects using disk: basic
Content Delivery Network via Amazon Web Services: CloudFront: cloudfront.vmtoday.com

Served from: vmtoday.com @ 2012-02-08 19:23:26 -->
