<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://aznot.com/index.php?action=history&amp;feed=atom&amp;title=VMworld_2015%2FvSphere_6_Security_Update</id>
	<title>VMworld 2015/vSphere 6 Security Update - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://aznot.com/index.php?action=history&amp;feed=atom&amp;title=VMworld_2015%2FvSphere_6_Security_Update"/>
	<link rel="alternate" type="text/html" href="https://aznot.com/index.php?title=VMworld_2015/vSphere_6_Security_Update&amp;action=history"/>
	<updated>2026-05-09T00:13:26Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.41.0</generator>
	<entry>
		<id>https://aznot.com/index.php?title=VMworld_2015/vSphere_6_Security_Update&amp;diff=2458&amp;oldid=prev</id>
		<title>Kenneth at 20:06, 1 September 2015</title>
		<link rel="alternate" type="text/html" href="https://aznot.com/index.php?title=VMworld_2015/vSphere_6_Security_Update&amp;diff=2458&amp;oldid=prev"/>
		<updated>2015-09-01T20:06:18Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;vSphere Hardening Guide - READ IT&lt;br /&gt;
&lt;br /&gt;
by Mike Foley&lt;br /&gt;
&lt;br /&gt;
#INF4758 on Twitter&lt;br /&gt;
&lt;br /&gt;
http://blogs.vmware.com/vsphere/author/mike_foley&lt;br /&gt;
&lt;br /&gt;
Twitter: @vSphereSecurity&lt;br /&gt;
&lt;br /&gt;
VMware Security Hardening Guides | United States - http://www.vmware.com/security/hardening-guides&lt;br /&gt;
&lt;br /&gt;
vSphere 6.0 Hardening Guide – Overview of coming changes - VMware vSphere Blog - VMware Blogs - https://blogs.vmware.com/vsphere/2015/02/vsphere-6-0-hardening-guide-overview-coming-changes.html&lt;br /&gt;
&lt;br /&gt;
vSphere is secure out of the box, so this guide is more of an &amp;quot;auditing&amp;quot; guide.&lt;br /&gt;
&lt;br /&gt;
Prepares system for operational readiness&lt;br /&gt;
* auditing, control, active directory, ntp, syslog&lt;br /&gt;
&lt;br /&gt;
May disable some ease-of-use features&lt;br /&gt;
* features meant for POC and test environments&lt;br /&gt;
&lt;br /&gt;
Reduces attack surface - disabled un-used functionality&lt;br /&gt;
&lt;br /&gt;
Provides audit guidelines for compliance standards (PCI, HIPAA, SOX, DISA, etc)&lt;br /&gt;
&lt;br /&gt;
Makes the product less susceptible to threats and vulnerabilities&lt;br /&gt;
&lt;br /&gt;
Acts as a tool to generate discussion on risk management&lt;br /&gt;
&lt;br /&gt;
vSphere 6 Hardening Guide - major improvements&lt;br /&gt;
* cleaned up&lt;br /&gt;
* easier to implement&lt;br /&gt;
* new focus on programmatic guidance&lt;br /&gt;
* goal to be mostly accessible via APIs and/or CLIs&lt;br /&gt;
* automation, automation, automation&lt;br /&gt;
* leverage vsphere APIs&lt;br /&gt;
* easier to produce&lt;br /&gt;
&lt;br /&gt;
Programmatic Guidance vs Operational Guidance&lt;br /&gt;
* Science vs Art&lt;br /&gt;
&lt;br /&gt;
Operational Guidance becomes &amp;quot;best practices&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Old guide grouped by tabs.  New guide now a flat namespace (taxonomy), easier to parse through.&lt;br /&gt;
&lt;br /&gt;
vCheck Hardening Guide plugin - free powershell script that can send a daily update on various statuses (recommended)&lt;br /&gt;
&lt;br /&gt;
Major security enhancements in vSphere 6.0:&lt;br /&gt;
* increased flexibility in lockdown mode&lt;br /&gt;
* added cac smart card authentication to dcui (fed customers only)&lt;br /&gt;
* improved esxi password and account management&lt;br /&gt;
* enhanced auditing of admin actions&lt;br /&gt;
* certificate lifecycle management for vcenter and esxi&lt;br /&gt;
&lt;br /&gt;
all sorts of new commands added to esxcli&lt;br /&gt;
&lt;br /&gt;
Flexible Lockdown Mode:&lt;br /&gt;
* Normal and Strict (DCUI stopped)&lt;br /&gt;
&lt;br /&gt;
vSphere 6.0 Certificate Manager - generate SSL and CSRs&lt;br /&gt;
&lt;br /&gt;
VMCA - VMware Certificate Authority&lt;/div&gt;</summary>
		<author><name>Kenneth</name></author>
	</entry>
</feed>