STIGQter STIGQter: STIG Summary:

Rancher Government Solutions Multi-Cluster Manager Security Technical Implementation Guide

Version: 2

Release: 2 Benchmark Date: 05 Jan 2026

CheckedNameTitle
SV-252843r1043176_ruleRancher MCM must use a centralized user management solution to support account management functions. For accounts using password authentication, the container platform must use FIPS-validated SHA-2 or later protocol to protect the integrity of the password authentication process.
SV-252844r960777_ruleRancher MCM must generate audit records for all DoD-defined auditable events within all components in the platform.
SV-252845r960783_ruleWhen allowed by the central authentication system, the default role assigned to a user must be User-Base.
SV-252846r960900_ruleRancher MCM must allocate audit record storage and generate audit records associated with events, users, and groups.
SV-252847r971528_ruleRancher MCM must never automatically remove or disable emergency accounts.
SV-252849r1155126_ruleRancher MCM must prohibit or restrict the use of protocols that transmit unencrypted authentication information or use flawed cryptographic algorithms for transmission.
SV-257292r961287_ruleRancher MCM must enforce organization-defined circumstances and/or usage conditions for organization-defined accounts.