Check: SRG-APP-000014-CTR-000040
Container Platform SRG:
SRG-APP-000014-CTR-000040
(in versions v1 r5 through v1 r1)
Title
The container platform must use TLS 1.2 or greater for secure communication. (Cat II impact)
Discussion
The authenticity and integrity of the container platform and communication between nodes and components must be secure. If an insecure protocol is used during transmission of data, the data can be intercepted and manipulated. The manipulation of data can be used to inject status changes of the container platform, causing the execution of containers or reporting an incorrect healthcheck. To thwart the manipulation of the data during transmission, a secure protocol (TLS 1.2 or newer) must be used. Further guidance on secure transport protocols can be found in NIST SP 800-52.
Check Content
Review the container platform configuration to verify that TLS 1.2 or greater is being used for communication by the container platform nodes and components. If TLS 1.2 or greater is not being used for secure communication, this is a finding.
Fix Text
Configure the container platform to use TLS 1.2 or greater for node and component communication.
Additional Identifiers
Rule ID: SV-233016r879519_rule
Vulnerability ID: V-233016
Group Title: SRG-APP-000014
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000068 |
The information system implements cryptographic mechanisms to protect the confidentiality of remote access sessions. |
Controls
Number | Title |
---|---|
AC-17 (2) |
Protection Of Confidentiality / Integrity Using Encryption |