6.6

Table Of Contents
Index
A
administrative accounts 13
agent certificate revocation 36
apache configuration 27
Apache httpd 21
application resources, protect 25
auditing 49
authorized NTP server 49
B
best practices, End Point Operations
Management agents 31
Bluetooth protocol handler 28
boot loader authentication 17
browser considerations 49
C
cipher suites in GemFire 23
cipher suites in Apache httpd 23
client configuration, secure shell 16
configuration, PostgreSQL client
authentication 26
configuration modes, disable 28
configure 28
configure network settings for OVF 39
configure network time protocol 20
console access 13
D
data in transit 21
Datagram Congestion Control Protocol 29
DECnet Protocol, secure 30
deny forwarding 43
deny ICMPv4 echoes to broadcast address 40
deny IPv6 router settings 46
deny IPv6 router advertisement hop limit 46
disable, unnecessary applications 37
disable browsing 27
disable direct logins 17
disable directory browsing 27
disable SSH access for the admin user
account 17
disable TCP timestamp response 20
disable the trace method:Apache2 server 27
disable unnecessary ports 37
disable unnecessary services 37
E
enable TLS on PostgreSQL 25
enabling FIPS 140-2 mode 20
enabling TLS 24
End Point Operations Management agent 31
F
file permissions, secure shell 15
G
GemFire TLS handler protocols 21
generate a self-signed certificate with
OpenSSL 24
glossary 5
H
hardening infrastructure 9
hardening for Linux installation 10
hardening the vSphere environment 10
I
infrastructure, hardening 9
install the certificate for PostgreSQL 24
intended audience 5
inventory of unsupported software 10
IPV4 source routed packets 43
IPv4, deny 1Pv4 forwarding 42
IPv4, deny IPv4 ICMP redirects 41
IPv4, disable proxy ARP 40
IPv4, ignore ICMP redirect messages 40
IPv4, ignore IPv4 reverse path filtering 42
IPv4, log IPv4 Martian packets 42
IPv4, use IPv4 TCP syncookies 44
IPv6 autoconf settings 46
IPv6, deny IPv6 forwarding 43
IPv6, deny IPv6 neighbor solicitations 47
IPv6, deny IPv6 router advertisements 44
IPv6, deny IPv6 router prefix 45
IPv6, deny IPv6 router solicitations 45
IPv6, deny IPv6 router preference in router
solicitations 45
IPv6, ignore ICMP redirect messages 41
IPv6, restrict IPv6 maximum addresses 47
VMware, Inc.
51