HOWTO
VMWARE
POST INSTALL PROCEDURES TO SECURE A VMWARE ESXI HOST

Published: 20190329

Tested on:
VMware ESXi 6.7.0 (Build 8169922)

-

If you follow the procedures in order, you wont compromise security.
In this guide we assume the hostname of your VMware ESXi host is "vmwarehost".
You also need to create an openssl key-file and crt-file, their names are assumed to be: custom.key and custom.crt

Instructions how to create your own CA and include it in your browser can be found here

  1. Enable SSH

  2. Verify the SSH fingerprint

  3. Change RSA key to 4096 bits

  4. Optional - Upload your own SSH public key to use for login

  5. Upload key & cert to the VMware Web UI