Rancher MCM must use a centralized user management solution to support account management functions. For accounts using password authentication, the container platform must use FIPS-validated SHA-2 or later protocol to protect the integrity of the password authentication process.
DISA Rule
SV-252843r1043176_rule
Vulnerability Number
V-252843
Group Title
SRG-APP-000023-CTR-000055
Rule Version
CNTR-RM-000030
Severity
CAT I
CCI(s)
- CCI-000015 - Support the management of system accounts using (organization-defined automated mechanisms).
- CCI-000016 - Automatically remove or disable temporary and emergency accounts after an organization-defined time-period for each type of account.
- CCI-000044 - Enforce the organization-defined limit of consecutive invalid logon attempts by a user during the organization-defined time period.
- CCI-000134 - Ensure that audit records containing information that establishes the outcome of the event.
- CCI-000154 - Provide the capability to centrally review and analyze audit records from multiple components within the system.
- CCI-000162 - Protect audit information from unauthorized access.
- CCI-000163 - Protect audit information from unauthorized modification.
- CCI-000164 - Protect audit information from unauthorized deletion.
- CCI-000187 - For public key-based authentication, map the authenticated identity to the account of the individual or group.
- CCI-004066 - For password-based authentication, enforce organization-defined composition and complexity rules.
- CCI-004062 - For password-based authentication, store passwords using an approved salted key derivation function, preferably using a keyed hash.
- CCI-000197 - For password-based authentication, transmit passwords only cryptographically-protected channels.
- CCI-004061 - For password-based authentication, verify when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a).
- CCI-000206 - Obscure feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unauthorized individuals.
- CCI-000213 - Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
- CCI-000764 - Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
- CCI-000765 - Implement multifactor authentication for network access to privileged accounts.
- CCI-000766 - Implement multifactor authentication for network access to non-privileged accounts.
- CCI-003627 - Disable accounts when the accounts have expired.
- CCI-001090 - Prevent unauthorized and unintended information transfer via shared system resources.
- CCI-001350 - Implement cryptographic mechanisms to protect the integrity of audit information.
- CCI-001368 - Enforce approved authorizations for controlling the flow of information within the system based on organization-defined information flow control policies.
- CCI-001403 - Automatically audit account modification actions.
- CCI-001493 - Protect audit tools from unauthorized access.
- CCI-001494 - Protect audit tools from unauthorized modification.
- CCI-001495 - Protect audit tools from unauthorized deletion.
- CCI-001499 - Limit privileges to change software resident within software libraries.
- CCI-001764 - Prevent program execution in accordance with organization-defined policies, rules of behavior, and/or access agreements regarding software program usage and restrictions; rules authorizing the terms and conditions of software program usage.
- CCI-003980 - Allow user installation of software only with explicit privileged status.
- CCI-001813 - Enforce access restrictions using organization-defined mechanisms.
- CCI-003938 - Automatically generate audit records of the enforcement actions.
- CCI-001941 - Implement replay-resistant authentication mechanisms for access to privileged accounts and/or non-privileged accounts.
- CCI-004045 - Require users to be individually authenticated before granting access to the shared accounts or resources.
- CCI-002235 - Prevent non-privileged users from executing privileged functions.
- CCI-002238 - Automatically lock the account or node for either an organization-defined time period, until the locked account or node is released by an administrator, or delays the next logon prompt according to the organization-defined delay algorithm when the maximum number of unsuccessful logon attempts is exceeded.
Weight
10
Fix Recommendation
RBAC Integration and Authn/Authz
Navigate to Triple Bar Symbol(Global) >> Users & Authentication >> Auth Provider.
From this screen the authentication mechanism can be selected and configured.
This STIG is written and tested with KeyCloak and not included with Rancher MCM. Installation instructions for KeyCloak can be found here:
https://www.keycloak.org/getting-started/getting-started-kube
Check Contents
RBAC Integration and Authn/Authz
View and modify authentication settings through the Rancher MCM UI.
Navigate to Triple Bar Symbol(Global) >> Users & Authentication >> Auth Provider.
This screen shows the authentication mechanism that is configured. If no authentication mechanism is configured or disabled, this is a finding.
Vulnerability Number
V-252843
Documentable
False
Rule Version
CNTR-RM-000030
Severity Override Guidance
RBAC Integration and Authn/Authz
View and modify authentication settings through the Rancher MCM UI.
Navigate to Triple Bar Symbol(Global) >> Users & Authentication >> Auth Provider.
This screen shows the authentication mechanism that is configured. If no authentication mechanism is configured or disabled, this is a finding.
Check Content Reference
M
Target Key
5467