• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

Yellow Bricks

by Duncan Epping

  • Home
  • Unexplored Territory Podcast
  • HA Deepdive
  • ESXTOP
  • Stickers/Shirts
  • Privacy Policy
  • About
  • Show Search
Hide Search

vSphere Security Hardening Guide script by @lamw

Duncan Epping · Feb 8, 2010 ·

A couple of weeks ago I blogged about the vSphere Security Hardening Guide. Just a couple of days later William “the king of Perl” Lam already produced a script that checks the Hardening Guide best practices against your environment. It produces a great html based report.

Source

While going through the COS/HOST and VM documentation, I noticed there were quite a few checks that might benefit from having a script to validate the guidelines and that was the motivation for this script. Not all sections can be validated using the vSphere APIs and will require some manual validation and I’ve seperated the types of passes whether it’s a fail, pass or manual (which requires user intervention).

The script allows you to run the current existing guides as of (01/29/2010) against vCenter 4.0 hosting ESX(i) 4.0 hosts/virtual machines OR run it against an individual ESX(i) 4.0 host. The script allows you to run a subset of the checks and against different type of validation (ENTERPRISE,DMZ or SSLF). Upon completion, a report is generated including a grade for your environment.

A couple of details on the features:

  • Email report
  • Ability to execute subset of the checks (COS,HOST,VCENTER,VNETWORK,VM)
  • Ability execute specific test suite (ENTERPRISE,DMZ,SSLF)
  • Detail HTML summary report with letter grade

You can find an example report here. Great work again William, keep it up!

Related

Server ESX, esxi, vcenter, VMware, vSphere

Reader Interactions

Comments

  1. Doug says

    9 February, 2010 at 23:15

    I tried running this against a test ESX 4 Update 1 host, and it moaned about software version incompatability. Assume this hasn’t been tested against/written for U1 yet?

  2. William Lam says

    13 February, 2010 at 17:07

    Hi Doug,

    This was tested again ESXi 4.0u1 hosts which should also work for classic ESX 4.0u1, unfortunately I don’t have enough capacity to deploy another to verify.

    If you can paste the error you’re seeing on: http://communities.vmware.com/docs/DOC-11901 I can take a look when I get a chance.

    Thanks

    –William

  3. David Beaudet says

    21 July, 2011 at 15:13

    Anything similar exist for the 4.1 version?

  4. Piet says

    2 December, 2011 at 10:25

    And 5.0 ?

Primary Sidebar

About the Author

Duncan Epping is a Chief Technologist and Distinguished Engineering Architect at Broadcom. Besides writing on Yellow-Bricks, Duncan is the co-author of the vSAN Deep Dive and the vSphere Clustering Deep Dive book series. Duncan is also the host of the Unexplored Territory Podcast.

Follow Us

  • X
  • Spotify
  • RSS Feed
  • LinkedIn

Recommended Book(s)

Advertisements




Copyright Yellow-Bricks.com © 2025 · Log in