6.7

Table Of Contents
Contents
About vSphere Security 7
1
Security in the vSphere Environment 9
Securing the ESXi Hypervisor 9
Securing vCenter Server Systems and Associated Services 11
Securing Virtual Machines 12
Securing the Virtual Networking Layer 13
Passwords in Your vSphere Environment 15
Security Best Practices and Resources 16
2
vSphere Permissions and User Management Tasks 18
Understanding Authorization in vSphere 19
Managing Permissions for vCenter Components 25
Global Permissions 28
Using Roles to Assign Privileges 31
Best Practices for Roles and Permissions 34
Required Privileges for Common Tasks 35
3
Securing ESXi Hosts 39
General ESXi Security Recommendations 39
Certificate Management for ESXi Hosts 51
Customizing Hosts with the Security Profile 67
Assigning Privileges for ESXi Hosts 83
Using Active Directory to Manage ESXi Users 86
Using vSphere Authentication Proxy 88
Configuring Smart Card Authentication for ESXi 96
Using the ESXi Shell 98
UEFI Secure Boot for ESXi Hosts 102
Securing ESXi Hosts with Trusted Platform Module 105
ESXi Log Files 107
4
Securing vCenter Server Systems 110
vCenter Server Security Best Practices 110
Verify Thumbprints for Legacy ESXi Hosts 116
Verify that SSL Certificate Validation Over Network File Copy Is Enabled 117
Required Ports for vCenter Server and Platform Services Controller 118
Additional vCenter Server TCP and UDP Ports 123
VMware, Inc.
3