VMWare probe passing clear text credentials
search cancel

VMWare probe passing clear text credentials

book

Article ID: 135154

calendar_today

Updated On:

Products

DX Unified Infrastructure Management (Nimsoft / UIM)

Issue/Introduction

We were informed by our security team that credentials being passed from the VMWare probe to login to the VCenter server is being sent as clear text.  I see the probe has TLS 1.2 capability if VCenter supports it.  Do you know if communication is utilizing TLS 1.2, will the credentials be encrypted, or is this some other setting?  We are using VMWare probe version 7.14.

Environment

Release : 8.5

Component : UIM - VMWARE

Cause

NA

Resolution

Yes, the vmware probe is able to communicate over TLSv1.2 as of vmware probe v7.11 or higher.

See:

https://techdocs.broadcom.com/us/en/ca-enterprise-software/it-operations-management/ca-unified-infrastructure-management-probes/GA/alphabetical-probe-articles/vmware-vmware-monitoring/vmware-vmware-monitoring-release-notes.html

 

For TLS 1.2 support:

As the administrator of the target vCenter’s you may have enabled or disabled any version of TLS and the VMware probe will be able to communicate with the vCenter.

 

VMware probe will always initiate the handshake with TLS 1.2 and if the target vCenter supports TLS 1.2, all further communication will use the TLS 1.2 protocol. Otherwise, the highest protocol supported by the vCenter will be used.