SV-235811r627560_rule
V-235811
SRG-APP-000141
DKER-EE-002060
CAT II
10
This fix only applies to the use of Docker Engine - Enterprise on a Linux host operating system.
Do not start a container with --uts=host argument.
For example, do not start a container as below:
docker run --rm --interactive --tty --uts=host rhel7.2
This check only applies to the use of Docker Engine - Enterprise on a Linux host operating system and should be executed on all nodes in a Docker Enterprise cluster.
Ensure the host's UTS namespace is not shared.
via CLI:
Linux: As a Docker EE Admin, execute the following command using a Universal Control Plane (UCP) client bundle:
docker ps --quiet --all | xargs docker inspect --format '{{ .Id }}: UTSMode={{ .HostConfig.UTSMode }}'
If the above command returns host, it means the host UTS namespace is shared with the container and this is a finding.
V-235811
False
DKER-EE-002060
This check only applies to the use of Docker Engine - Enterprise on a Linux host operating system and should be executed on all nodes in a Docker Enterprise cluster.
Ensure the host's UTS namespace is not shared.
via CLI:
Linux: As a Docker EE Admin, execute the following command using a Universal Control Plane (UCP) client bundle:
docker ps --quiet --all | xargs docker inspect --format '{{ .Id }}: UTSMode={{ .HostConfig.UTSMode }}'
If the above command returns host, it means the host UTS namespace is shared with the container and this is a finding.
M
5281