6.5

Table Of Contents
Index
A
administrative accounts 15
agent certificate revocation 39
apache configuration 28
Apache httpd 23
application resources, protect 26
auditing 51
authorized NTP server 51
B
best practices, End Point Operations
Management agents 34
Bluetooth protocol handler 29
boot loader authentication 19
browser considerations 51
C
cipher suites in GemFire 25
cipher suites in Apache httpd 25
client configuration, secure shell 18
configuration, PostgreSQL client
authentication 27
configuration modes, disable 29, 34
configure 29
configure network settings for OVF 41
configure network time protocol 22
configure strong protocols 33
console access 15
D
data in transit 23, 33
Datagram Congestion Control Protocol 30
DECnet Protocol, secure 31
deny forwarding 45
deny ICMPv4 echoes to broadcast address 42
deny IPv6 router settings 48
deny IPv6 router advertisement hop limit 48
Diffie-Hellman 33
disable, unnecessary applications 39
disable browsing 28
disable direct logins 19
disable directory browsing 28
disable SSH access for the admin user
account 19
disable TCP timestamp response 22
disable the trace method:Apache2 server 28
disable unnecessary ports 40
disable unnecessary services 40
disable weak ciphers 33
E
enabling FIPS 140-2 mode 22
End Point Operations Management agent 34
F
file permissions, secure shell 17
G
GemFire TLS handler protocols 23
glossary 5
H
hardening infrastructure 9
hardening for Linux installation 10
hardening the vSphere environment 10
host server secure configuration 34
I
infrastructure, hardening 9
intended audience 5
inventory of unsupported software 10
IPV4 source routed packets 45
IPv4, deny 1Pv4 forwarding 44
IPv4, deny IPv4 ICMP redirects 43
IPv4, disable proxy ARP 42
IPv4, ignore ICMP redirect messages 42
IPv4, ignore IPv4 reverse path filtering 44
IPv4, log IPv4 Martian packets 44
IPv4, use IPv4 TCP syncookies 46
IPv6 autoconf settings 48
IPv6, deny IPv6 forwarding 45
IPv6, deny IPv6 neighbor solicitations 49
IPv6, deny IPv6 router advertisements 46
IPv6, deny IPv6 router prefix 47
IPv6, deny IPv6 router solicitations 47
IPv6, deny IPv6 router preference in router
solicitations 47
IPv6, ignore ICMP redirect messages 43
IPv6, restrict IPv6 maximum addresses 49
VMware, Inc.
53