6.5.1

Table Of Contents
See Storage Security Best Practices.
Evaluate the use of
IPSec
ESXi supports IPSec over IPv6. You cannot use IPSec over IPv4.
See Internet Protocol Security.
In addition, evaluate whether VMware NSX for vSphere is a good solution for securing the networking
layer in your environment.
Passwords in Your vSphere Environment
Password restrictions, password expiration, and account lockout in your vSphere environment depend on
the system that the user targets, who the user is, and how policies are set.
ESXi Passwords
ESXi password restrictions are determined by the Linux PAM module pam_passwdqc. See the Linux
manpage for pam_passwdqc and see ESXi Passwords and Account Lockout.
Passwords for vCenter Server and Other vCenter Services
vCenter Single Sign-On manages authentication for all users who log in to vCenter Server and other
vCenter services. The password restrictions, password expiration, and account lockout depend on the
user's domain and on who the user is.
vCenter Single Sign-On
Administrator
The password for the vCenter Single Sign-On administrator is
administrator@vsphere.local by default or administrator@mydomain if you
specified a different domain during installation. This password does not
expire. In all other regards, the password must follow the restrictions that
are set in the vCenter Single Sign-On password policy. See Platform
Services Controller Administration for details.
If you forget the password for this user, search the VMware Knowledge
Base system for information on resetting this password. The reset requires
additional privileges such as root access to the vCenter Server system.
Other Users of the
vCenter Single Sign-On
Domain
Passwords for other vsphere.local users, or users of the domain that you
specified during installation, must follow the restrictions that are set by the
vCenter Single Sign-On password policy and lockout policy. See Platform
Services Controller Administration for details. These passwords expire after
90 days by default. Administrators can change the expiration as part of the
password policy.
If you forget your vsphere.local password, an administrator user can reset
the password using the dir-cli command.
Other Users Password restrictions, password expiration, and account lockout for all
other users are determined by the domain (identity source) to which the
user can authenticate.
vSphere Security
VMware, Inc. 16