STIGQter STIGQter: STIG Summary: Rancher Government Solutions Multi-Cluster Manager Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 05 Jan 2026:

Rancher MCM must use a centralized user management solution to support account management functions. For accounts using password authentication, the container platform must use FIPS-validated SHA-2 or later protocol to protect the integrity of the password authentication process.

DISA Rule

SV-252843r1043176_rule

Vulnerability Number

V-252843

Group Title

SRG-APP-000023-CTR-000055

Rule Version

CNTR-RM-000030

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

RBAC Integration and Authn/Authz

Navigate to Triple Bar Symbol(Global) >> Users & Authentication >> Auth Provider.

From this screen the authentication mechanism can be selected and configured.

This STIG is written and tested with KeyCloak and not included with Rancher MCM. Installation instructions for KeyCloak can be found here:

https://www.keycloak.org/getting-started/getting-started-kube

Check Contents

RBAC Integration and Authn/Authz

View and modify authentication settings through the Rancher MCM UI.

Navigate to Triple Bar Symbol(Global) >> Users & Authentication >> Auth Provider.

This screen shows the authentication mechanism that is configured. If no authentication mechanism is configured or disabled, this is a finding.

Vulnerability Number

V-252843

Documentable

False

Rule Version

CNTR-RM-000030

Severity Override Guidance

RBAC Integration and Authn/Authz

View and modify authentication settings through the Rancher MCM UI.

Navigate to Triple Bar Symbol(Global) >> Users & Authentication >> Auth Provider.

This screen shows the authentication mechanism that is configured. If no authentication mechanism is configured or disabled, this is a finding.

Check Content Reference

M

Target Key

5467