<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Script to allow ESX to pass a DISA Security Readiness Review</title>
	<atom:link href="http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/</link>
	<description>A home for all things TechnoGeeky</description>
	<lastBuildDate>Thu, 04 Feb 2010 07:43:52 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Philip Morrison</title>
		<link>http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/comment-page-1/#comment-205</link>
		<dc:creator>Philip Morrison</dc:creator>
		<pubDate>Thu, 21 Aug 2008 22:35:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/#comment-205</guid>
		<description>I think I answered this in the VMTN but in case I didnt (ive been on a bunch of planes lately)...
/var/log/ESX_SRRSecure.timestamp should have the output of the results.</description>
		<content:encoded><![CDATA[<p>I think I answered this in the VMTN but in case I didnt (ive been on a bunch of planes lately)&#8230;<br />
/var/log/ESX_SRRSecure.timestamp should have the output of the results.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BacMan</title>
		<link>http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/comment-page-1/#comment-204</link>
		<dc:creator>BacMan</dc:creator>
		<pubDate>Thu, 21 Aug 2008 04:58:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/#comment-204</guid>
		<description>Thanks Philip.

Also, for the ESX script, is there a way to output the result to a log file for later review. As I have noticed when I ran the script it has some errors but it went by too fast. Or, is there a way to pause the script at certain point to see what is going on?

I am new to UNXIX and shell scripting. Thanks again for your help and much appreciated.

Cheers,</description>
		<content:encoded><![CDATA[<p>Thanks Philip.</p>
<p>Also, for the ESX script, is there a way to output the result to a log file for later review. As I have noticed when I ran the script it has some errors but it went by too fast. Or, is there a way to pause the script at certain point to see what is going on?</p>
<p>I am new to UNXIX and shell scripting. Thanks again for your help and much appreciated.</p>
<p>Cheers,</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Philip Morrison</title>
		<link>http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/comment-page-1/#comment-203</link>
		<dc:creator>Philip Morrison</dc:creator>
		<pubDate>Wed, 20 Aug 2008 22:43:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/#comment-203</guid>
		<description>when you run the SRR it creates a folder that is the same as the FQDN of the server you ran it on.  IF you told the SRR to only report open findings you should find a file there that should be the name-of-the-server.open  It should have all the open findings in txt format.</description>
		<content:encoded><![CDATA[<p>when you run the SRR it creates a folder that is the same as the FQDN of the server you ran it on.  IF you told the SRR to only report open findings you should find a file there that should be the name-of-the-server.open  It should have all the open findings in txt format.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BacMan</title>
		<link>http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/comment-page-1/#comment-202</link>
		<dc:creator>BacMan</dc:creator>
		<pubDate>Wed, 20 Aug 2008 01:30:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/#comment-202</guid>
		<description>Thanks Philip.

As a note,the doc above mentioned that you run the SRR and allowed the ESX server rebooted. Then, re-run the SRR script again and compare the result. Where the results are save as?

TIA</description>
		<content:encoded><![CDATA[<p>Thanks Philip.</p>
<p>As a note,the doc above mentioned that you run the SRR and allowed the ESX server rebooted. Then, re-run the SRR script again and compare the result. Where the results are save as?</p>
<p>TIA</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Philip Morrison</title>
		<link>http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/comment-page-1/#comment-199</link>
		<dc:creator>Philip Morrison</dc:creator>
		<pubDate>Thu, 07 Aug 2008 00:01:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/#comment-199</guid>
		<description>There is a way to do this from the command line.
vimsh -n -e /hostsvc/maintenance_mode_exit

This was going to be in the script but we decided not to do so since it could impact production environments.</description>
		<content:encoded><![CDATA[<p>There is a way to do this from the command line.<br />
vimsh -n -e /hostsvc/maintenance_mode_exit</p>
<p>This was going to be in the script but we decided not to do so since it could impact production environments.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BacMan</title>
		<link>http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/comment-page-1/#comment-198</link>
		<dc:creator>BacMan</dc:creator>
		<pubDate>Wed, 06 Aug 2008 23:04:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/#comment-198</guid>
		<description>In ESX SRR prerequisites that the ESX server need to be in the &quot;maintenance mode&quot;. Do you know how to do this from the console?

I guessed I can use VC to put the ESX server in the maintenance mode. But, just want to know if I can do it from CLI.

Thanks.</description>
		<content:encoded><![CDATA[<p>In ESX SRR prerequisites that the ESX server need to be in the &#8220;maintenance mode&#8221;. Do you know how to do this from the console?</p>
<p>I guessed I can use VC to put the ESX server in the maintenance mode. But, just want to know if I can do it from CLI.</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brian</title>
		<link>http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/comment-page-1/#comment-201</link>
		<dc:creator>Brian</dc:creator>
		<pubDate>Tue, 29 Jul 2008 13:44:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/#comment-201</guid>
		<description>Sorry, missed your June post with all this info....</description>
		<content:encoded><![CDATA[<p>Sorry, missed your June post with all this info&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brian</title>
		<link>http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/comment-page-1/#comment-200</link>
		<dc:creator>Brian</dc:creator>
		<pubDate>Tue, 29 Jul 2008 13:41:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/#comment-200</guid>
		<description>Just an update.... DISA now has/supports an ESX STIG and has released a checklist for it.

Also, the new DISA password requirements are 14 charcters, 2 upper, 2 lower, 2 number, 2 special.

This will also not apply to people running ESX 3i, as in embeded hardware installs from HP/Dell/etc.</description>
		<content:encoded><![CDATA[<p>Just an update&#8230;. DISA now has/supports an ESX STIG and has released a checklist for it.</p>
<p>Also, the new DISA password requirements are 14 charcters, 2 upper, 2 lower, 2 number, 2 special.</p>
<p>This will also not apply to people running ESX 3i, as in embeded hardware installs from HP/Dell/etc.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
