SV-257543r1015795_rule
V-257543
SRG-APP-000172-CTR-000440
CNTR-OS-000460
CAT I
10
Configure OpenShift to use an appropriate Identity Provider. Do not use HTPasswd. Use either LDAP(AD), OpenIDConnect or an approved identity provider.
To configure LDAP provider:
1. Create Secret for BIND DN password by executing the following:
oc create secret generic ldap-secret --from-literal=bindPassword=<secret> -n openshift-config
2. Create config map for LDAP Trust CA by executing the following:
oc create configmap ca-config-map --from-file=ca.crt=/path/to/ca -n openshift-config
3. Create LDAP Auth Config Resource YAML:
Using the preferred text editor, create a file named ldapidp.yaml using the example content (replacing config values as appropriate).
apiVersion: config.openshift.io/v1
kind: OAuth
metadata:
name: cluster
spec:
identityProviders:
- name: ldapidp
mappingMethod: claim
type: LDAP
ldap:
attributes:
id:
- dn
email:
- mail
name:
- cn
preferredUsername:
- uid
bindDN: <"bindDN">
bindPassword:
name: ldap-secret
ca:
name: ca-config-map
insecure: false
url: <URL>
4. Apply LDAP config to cluster by executing the following:
oc apply -f ldapidp.yaml
Note: For more information on configuring an LDAP provider, refer to https://docs.openshift.com/container-platform/4.8/authentication/identity_providers/configuring-ldap-identity-provider.html.
To configure OpenID provider:
1. Create Secret for Client Secret by executing the following:
oc create secret generic idp-secret --from-literal=clientSecret=<secret> -n openshift-config
2. Create config map for OpenID Trust CA by executing the following:
oc create configmap ca-config-map --from-file=ca.crt=/path/to/ca -n openshift-config
3. Create OpenID Auth Config Resource YAML.
Using your preferred text editor, create a file named oidcidp.yaml using the example content (replacing config values as appropriate).
apiVersion: config.openshift.io/v1
kind: OAuth
metadata:
name: cluster
spec:
identityProviders:
- name: oidcidp
mappingMethod: claim
type: OpenID
openID:
clientID: <clientID>
clientSecret:
name: oidc-idp-secret
claims:
preferredUsername:
- preferred_username
name:
- name
email:
- email
ca:
name: ca-config-map
issuer: <URL>
4. Apply OpenID config to cluster by executing the following:
oc apply -f ldapidp.yaml
Note: For more information on configuring an OpenID provider, refer to https://docs.openshift.com/container-platform/4.8/authentication/identity_providers/configuring-oidc-identity-provider.html.
Verify the authentication operator is configured to use either an LDAP or a OpenIDConnect provider by executing the following:
oc get oauth cluster -o jsonpath="{.spec.identityProviders[*].type}{'\n'}"
If the output lists any other type besides LDAP or OpenID, this is a finding.
V-257543
False
CNTR-OS-000460
Verify the authentication operator is configured to use either an LDAP or a OpenIDConnect provider by executing the following:
oc get oauth cluster -o jsonpath="{.spec.identityProviders[*].type}{'\n'}"
If the output lists any other type besides LDAP or OpenID, this is a finding.
M
5547