11.07.2015 Views

vrealize-automation-62-hardening

vrealize-automation-62-hardening

vrealize-automation-62-hardening

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

VMware vRealize Automation 6.2 Hardening GuidevRealize Hardening Tool CategoriesThe following table correlates the <strong>hardening</strong> activity with the UI and command line options.Hardening Activity UI Option Command Line TagApache Server Response Header Apache2 Configuration apache2Create Local Administrative Account Linux Admin Usercreate_admin_userFor SSHLighttpd Server Response Headers Lighttpd Configuration lighttpdConfigure NTP Network Time Protocol ntpModify root Password Expiry Root Password Expiry pwd_expiryDisabling SSLv3 on RabbitMQ RabbitMQ Configuration rabbitmqTcserver Response Server Header TcServer Configuration tcserverSecure DeploymentVerifying the Integrity of Installation MediaVerify the integrity of the installation media before you install the product.Always verify the SHA1 hash after you download an ISO, offline bundle, or patch to ensure integrity and authenticityof the downloaded files. If you obtain physical media from VMware and the security seal is broken, return the softwareto VMware for a replacement.After you download the media, use the MD5/SHA1 sum value to verify the integrity of the download. Compare theMD5/SHA1 hash output with the value posted on the VMware Web site. SHA1 or MD5 hash should match.For more information about verifying the integrity of the installation media, see http://kb.vmware.com/kb/1537.Hardening InfrastructureHardening the VMware vSphere EnvironmentvRealize Automation relies on a secure VMware vSphere environment to achieve the greatest benefits and a securedinfrastructure.Assess the VMware vSphere environment and verify that the appropriate level of vSphere <strong>hardening</strong> guidance isenforced and maintained.For more guidance about <strong>hardening</strong>, see http://www.vmware.com/security/<strong>hardening</strong>-guides.html.Verify Hardening of the Infrastructure as a Service HostReview the recommendations set out in the appropriate Windows <strong>hardening</strong> and secure best practice guidelines, andensure that your Windows Server host is appropriately hardened. Not following the <strong>hardening</strong> recommendations mightresult in exposure to known security vulnerabilities from insecure components on Windows releases.To verify that your version is supported, see the vRealize Automation Support Matrix.Contact your Microsoft vendor about the correct guidance for <strong>hardening</strong> practices of Microsoft products.T E C H N I C A L W H I T E P A P E R / 9

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!