Configure Security Settings for vCenter Server from the vSphere Client
You perform the procedure on all vCenter Server instances to configure password policies, lockout policies, alarms, proxy, login banners, LDAP, and other configurations.
- In a Web browser, log in to vCenter Server by using the vSphere Client.SettingValueURLhttps://management-domain-vcenter-server-fqdn/uiUser nameadministrator@vsphere.local
- Configure the password policies.
- From theHomemenu of the vSphere Client, clickAdministration.
- UnderSingle Sign-On, clickConfiguration.
- On theLocal accountstab, underPassword policy, clickEdit.
- In theEdit password policiesdialog box, configure the settings and clickSave.Configuration IDSettingValueVMW-VC-00421Maximum lifetime60VMW-VC-00410Minimum Length15
- Configure the lockout policies.
- On theLocal accountstab, underLockout policy, clickEdit.
- In theEdit lockout policiesdialog box, configure the settings and clickSave.Configuration IDSettingValueVMW-VC-00436Maximum number of failed login attempts3VMW-VC-00434Time interval between failures900 secondsVMW-VC-00435Unlock time0 seconds
- VMW-VC-01219Configure an alert for the appropriate personnel about SSO account actions
- In theHosts and clustersinventory, select the vCenter Server that manages the ESXi host you configure.
- Click theConfiguretab, selectAlarm definitionsunderSecurity.
- ClickAdd.TheNew alarm definitionwizard opens.
- On theName and targetspage, enter the settings and clickNext.SettingValueAlarm nameSSO account actions - com.vmware.sso.PrincipalManagementTarget typevCenter Server
- On theAlarm rule 1page, underIf, entercom.vmware.sso.PrincipalManagementas a trigger and press Enter.
- Configure the remaining settings for the alarm, clickNext, and follow the prompts to finish the wizard.SettingValueTrigger the alarm andShow as warningSend email notificationsOffSend SNMP trapsOnRun scriptOff
- VMW-VC-00418Configure a proxy for the download of the public Hardware Compatibility List.
- In theHosts and Clustersinventory, select the vCenter Server that you configure.
- Click theConfiguretab and undervSAN, clickInternet connectivity.
- On theInternet connectivitypage, clickEdit.
- Select theConfigure the proxy server if your system uses onecheck box.
- Enter the proxy server details and clickApply.
- VMW-VC-01236Remove the privilege to use the virtual machine console for the standard virtual machine user role.
- On theHomepage of the vSphere Client, clickAdministration, and clickRoles.
- From theRoles providerdrop-down menu, select the vCenter Server that you configure.
- Select theVirtual machine user (sample)role and clickEdit role action.
- In theEdit roledialog box, select theVirtual machinegroup and underInteraction, deselect theConsole interactioncheck box.
- ClickNextand clickFinish.
- VMW-VC-01209Configure a login message.
- From theHomemenu of the vSphere Client, clickAdministration.
- Navigate to.
- Click theLogin messagetab and clickEdit.
- Activate theShow login messagetoggle.
- In theLogin messagetext box, enter the login message.
- Activate theConsent checkboxtoggle.
- In theDetails of login messagetext box, enter the site-specific banner text and clickSave.
- VMW-VC-01212Configure Mutual CHAP for vSAN iSCSI targets.
- In theHosts and Clustersinventory, select the vSAN-enabled cluster.
- Click theConfiguretab and undervSAN, clickServices.
- In thevSAN iSCSI target servicetile, clickEnable.
- Activate the service from the toggle switch.
- From theAuthenticationdrop-down menu, selectMutual CHAP
- Configure the incoming and outgoing users and secrets appropriately and clickApply.
- Set SDDC deployment details on the vCenter Server instances.
- In theGlobal inventory listsinventory, clickvCenter Servers.
- Click the vCenter Server object and click theConfiguretab in the central pane.
- UnderSettings, clickAdvanced settingsand clickEdit settings.
- In theEdit advanced vCenter Server settingsdialog box, enter the settings and clickAdd.
SettingValueNameconfig.SDDC.Deployed.ComplianceKitValueVCF-NIST-800-53 - VMW-VC-00422vCenter Server must terminate vSphere Client sessions after 10 minutes of inactivity.
- From theHomemenu of the vSphere Client, clickAdministration.
- UnderDeployment, clickClient configuration.
- ClickEdit, forSession timeout, enter10minutes, and clickSave.