ESX Agent Manager application files must be verified for their integrity.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-256680SRG-APP-000131-WSR-000051VCEM-70-000008SV-256680r918904_rule2023-06-151

Description

Verifying that ESX Agent Manager application code is unchanged from its shipping state is essential for file validation and nonrepudiation of the ESX Agent Manager. There is no reason the MD5 hash of the RPM original files should be changed after installation, excluding configuration files. Satisfies: SRG-APP-000131-WSR-000051, SRG-APP-000357-WSR-000150

ℹ️ Check

At the command prompt, run the following command: # rpm -V vmware-eam|grep "^..5......" | grep -v 'c /' | grep -v -E ".installer|.properties|.xml" If there is any output, this is a finding.

✔️ Fix

Reinstall the vCenter Server Appliance (VCSA) or roll back to a backup. Modifying the EAM installation files manually is not supported by VMware.