SV-235850r627677_rule
V-235850
SRG-APP-000516
DKER-EE-005080
CAT II
10
Run the below command to set the desired expiry time.
Example:
docker swarm update --cert-expiry 48h
Ensure node certificates are rotated as appropriate.
via CLI:
Linux: As a Docker EE Admin, follow the steps below using a Universal Control Plane (UCP) client bundle:
Run the below command and ensure that the node certificate Expiry Duration is set according to the System Security Plan (SSP).
docker info | grep "Expiry Duration"
If the expiry duration is not set according to the SSP, this is a finding.
V-235850
False
DKER-EE-005080
Ensure node certificates are rotated as appropriate.
via CLI:
Linux: As a Docker EE Admin, follow the steps below using a Universal Control Plane (UCP) client bundle:
Run the below command and ensure that the node certificate Expiry Duration is set according to the System Security Plan (SSP).
docker info | grep "Expiry Duration"
If the expiry duration is not set according to the SSP, this is a finding.
M
5281