For a customer we are required to perform a STIG hardening check.More info about the STIG hardening for Broadcom can be found here: https://www.cyber.mil/stigs/downloads
To perform these test (they can be done for all components within VCF in one check, or check the components seperatly) on NSX you need to obtain a cookie ID and a token. Once you collected these items, you need to enter these into a yaml file and execute the test. In the documentation can be found to find these items you need to execute the following command:
curl -k -i -X POST -d ‘j_username=myuser&j_password=mypassword’ https://<NSX-Manager>/api/session/create
In my environement I receive the following error message:
http/1.1 403 Forbidden
This error is caused by the fact that special characters are being used in the password causing problems with the encoding.
To resolve this issue we need to encode the username and password separatly, using –data-urlencode.
Example:curl -i -k -c cookies.txt -X POST --data-urlencode 'j_username=<username>' --data-urlencode 'j_password=<password>' https://<NSX-Manager>/api/session/create
Note: Replace <NSX-Manager>, <username> and <password> with the correct details.
Now the command completes succesfull and you can collect the required data.