A couple of months ago I blogged about the draft version of the vSphere Security Hardening Guide. Yesterday VMware published the first official version. Keep in mind that any feedback is still highly appreciated and the document is still subject to change. source article This document is the official release of the vSphere 4.0 Security Hardening Guide. This version is [...]
One of my former colleagues(who wants to remain anonymous) notified me about this. Although many of you might not even be doing this, for just the few who are it is useful to know this caveat. For security reasons some customers have the requirement to insert specific account information for every user. It appears that when you modify the details for [...]
I was working on a vShield Zones setup a couple of days ago. I have been a couple of times already but somehow the following details seem to slip every time and I find myself digging it up in the manual, hence the reason for this article. A reminder to myself: vShield Manager login(page 24): admin/default Configure IP Address with [...]
During the VCDX Defense panels one of the candidates mentioned using lock down mode for ESXi to add an extra layer of security. It seems that there is a common misunderstanding about the lockdown mode. Here’s how our documentation describes it: Enabling lockdown mode disables all direct root access to ESXi machines. Any subsequent local changes to the host must be [...]
We had an interesting discussion on one of the internal mailing lists this week. Someone asked what the general opinion was about disabling Tech Support. Of course some said disabling should not be a problem, but many also disagreed. The reason for this is simple: Support. When Tech Support is disabled it removes the option to login to the console [...]
I just received the following announcement and thought it would be interesting for you as well: HyTrust, Inc., the leader in policy management and access control for virtual infrastructure, announced today that it has secured $10.5 million in Series B financing. New investors Granite Ventures and Cisco Systems participated in the round of financing, as did existing investors Trident Capital [...]
I received a question from a customer who wanted, for security reasons, to remove the ESXi web welcome screen. This is the screen that enables you to download the vSphere Client and RCLI and even browse datastores. I’ve tested it and removing (or renaming) the following file will lead to a blank page when the ESXi host is accessed via [...]






