SRG-APP-000219-CTR-000550 Controls

STIG IDVersionTitleProduct
CNTR-K8-001400V2R4The Kubernetes API server must use approved cipher suites.
CNTR-K8-001410V2R4Kubernetes API Server must have the SSL Certificate Authority set.
CNTR-K8-001420V2R4Kubernetes Kubelet must have the SSL Certificate Authority set.
CNTR-K8-001430V2R4Kubernetes Controller Manager must have the SSL Certificate Authority set.
CNTR-K8-001440V2R4Kubernetes API Server must have a certificate for communication.
CNTR-K8-001450V2R4Kubernetes etcd must enable client authentication to secure service.
CNTR-K8-001460V2R4Kubernetes Kubelet must enable tlsPrivateKeyFile for client authentication to secure service.
CNTR-K8-001470V2R4Kubernetes Kubelet must enable tlsCertFile for client authentication to secure service.
CNTR-K8-001480V2R4Kubernetes etcd must enable client authentication to secure service.
CNTR-K8-001490V2R4Kubernetes etcd must have a key file for secure communication.
CNTR-K8-001500V2R4Kubernetes etcd must have a certificate for communication.
CNTR-K8-001510V2R4Kubernetes etcd must have the SSL Certificate Authority set.
CNTR-K8-001520V2R4Kubernetes etcd must have a certificate for communication.
CNTR-K8-001530V2R4Kubernetes etcd must have a key file for secure communication.
CNTR-K8-001540V2R4Kubernetes etcd must have peer-cert-file set for secure communication.
CNTR-K8-001550V2R4Kubernetes etcd must have a peer-key-file set for secure communication.
CNTR-OS-000510V1R1OpenShift must protect authenticity of communications sessions with the use of FIPS-validated 140-2 or 140-3 validated cryptography.