STIGQter STIGQter: STIG Summary: Mirantis Kubernetes Engine Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

MKE's self-signed certificates must be replaced with DOD trusted, signed certificates.

DISA Rule

SV-260927r966138_rule

Vulnerability Number

V-260927

Group Title

SRG-APP-000141-CTR-000320

Rule Version

CNTR-MK-000610

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If Kubernetes ingress is being used, this is Not Applicable.

Integrate MKE and MSR (if used) with a trusted certificate authority CA.

Log in to the MKE web UI and navigate to admin >> Admin Settings >> Certificates.

Either fill in the "CA Certificate" field with the contents of the external public CA certificate or upload a file.

Either fill in the "Server Certificate" and "Private Key" fields with the contents of the public/private certificates or upload a file.

The "Server Certificate" field must include both the MKE server certificate and any intermediate certificates.

Click "Save".

Check Contents

If Kubernetes ingress is being used, this is Not Applicable.

Check that MKE has been integrated with a trusted certificate authority (CA).

Log in to the MKE web UI and navigate to admin >> Admin Settings >> Certificates.

Click "Download MKE Server CA Certificate".

Verify that the contents of the downloaded "ca.pem" file match that of the trusted CA certificate.

If the certificate chain does not match the chain as defined by the System Security Plan (SSP), then this is a finding.

Vulnerability Number

V-260927

Documentable

False

Rule Version

CNTR-MK-000610

Severity Override Guidance

If Kubernetes ingress is being used, this is Not Applicable.

Check that MKE has been integrated with a trusted certificate authority (CA).

Log in to the MKE web UI and navigate to admin >> Admin Settings >> Certificates.

Click "Download MKE Server CA Certificate".

Verify that the contents of the downloaded "ca.pem" file match that of the trusted CA certificate.

If the certificate chain does not match the chain as defined by the System Security Plan (SSP), then this is a finding.

Check Content Reference

M

Target Key

5595