/
ESXi Certificate issues

ESXi Certificate issues


Product Name

CIS-CAT Pro Assessor

Product Version

v4.0.24+

Date

Dec 28, 2020



Problem

Even after reviewing this Knowledge Base article on assessing an ESXi Benchmark , CIS-CAT Pro Assessor v4 cannot connect to your ESXi host.

Solution

Review the ā€˜assessor-cli.logā€™ which was produced after following these steps for CIS-CAT Pro Assessor v4: https://cisecurity.atlassian.net/wiki/spaces/STPS/pages/728727902

Search for errors such as these VIServer errors:

14/10/2020 16:28:40.466 INFO org.cisecurity.powershell.impl.LocalPowershell - Response: Connect-VIServer : 10/14/2020 4:28:39 PM Connect-VIServer Error: Invalid server certificate.

or these again regarding VI errors

+ CategoryInfo : ObjectNotFound: (:) [Connect-VIServer], ViServerConnectionException + FullyQualifiedErrorId : Client20_ConnectivityServiceImpl_Reconnect_NameResolutionFailure,VMware.VimAutomation.Vi Core.Cmdlets.Commands.ConnectVIServer

or these, server certificate is not configured properly errors

20/10/2020 19:43:10.507 INFO org.cisecurity.powershell.impl.LocalPowershell - Response: Connect-VIServer : 2020-10-20 19:43:09 Connect-VIServer An error occurred while making the HTTP request to https://192.168.101.46/sdk. This could be due to the fact that the server certificate is not configured properly with HTTP.SYS in the HTTPS case. This could also be caused by a mismatch of the security binding between the client and the server.

Use Set-PowerCLIConfiguration to set the value for the InvalidCertificateAction option to Prompt if you'd like to connect once or to add a permanent exception for this server.

Remediation: The certificate must be ignored for the assessment to execute. In Powershell, execute the following command:

Ā 

Setting this option to ā€œIgnoreā€ should be reviewed against organizational policies.

Ā 

Ā 

Ā 


Copyright Ā© 2020

Center for Internet SecurityĀ®


Ā 

Related content

How to use CIS-CAT Pro Assessor v4 to assess VMWare ESXi
How to use CIS-CAT Pro Assessor v4 to assess VMWare ESXi
More like this
Getting Unknown Results on ESXi Assessment
Getting Unknown Results on ESXi Assessment
More like this
Quick Start Guide: ESXi Assessment using GUI (Windows)
Quick Start Guide: ESXi Assessment using GUI (Windows)
Read with this
Cannot connect to ESXi Target for Assessment
Cannot connect to ESXi Target for Assessment
More like this
End of Life (EOL) for CIS-CAT Pro Assessor v4 Service
End of Life (EOL) for CIS-CAT Pro Assessor v4 Service
Read with this
Remote assessment using WinRM is working for http but is failing for https.
Remote assessment using WinRM is working for http but is failing for https.
More like this