6.5.1

Table Of Contents
Contents
About vSphere Security 7
Updated Information 9
1
Security in the vSphere Environment 10
Securing the ESXi Hypervisor 10
Securing vCenter Server Systems and Associated Services 12
Securing Virtual Machines 13
Securing the Virtual Networking Layer 14
Passwords in Your vSphere Environment 16
Security Best Practices and Resources 17
2
vSphere Permissions and User Management Tasks 19
Understanding Authorization in vSphere 20
Managing Permissions for vCenter Components 26
Global Permissions 30
Using Roles to Assign Privileges 33
Best Practices for Roles and Permissions 36
Required Privileges for Common Tasks 37
3
Securing ESXi Hosts 41
Configure ESXi Hosts with Host Profiles 42
General ESXi Security Recommendations 42
Certificate Management for ESXi Hosts 53
Customizing Hosts with the Security Profile 69
Assigning Privileges for ESXi Hosts 85
Using Active Directory to Manage ESXi Users 88
Using vSphere Authentication Proxy 90
Configuring Smart Card Authentication for ESXi 98
Using the ESXi Shell 100
UEFI Secure Boot for ESXi Hosts 105
ESXi Log Files 108
4
Securing vCenter Server Systems 111
vCenter Server Security Best Practices 111
Verify Thumbprints for Legacy ESXi Hosts 117
Verify that SSL Certificate Validation Over Network File Copy Is Enabled 118
Required Ports for vCenter Server and Platform Services Controller 119
VMware, Inc.
3