SV-242441r712679_rule
V-242441
SRG-APP-000516-CTR-001325
CNTR-K8-002640
CAT II
10
Edit the Kubernetes API Server manifest file in the /etc/kubernetes/manifests directory on the Kubernetes Master Node. Set the value of "--kubelet-client-certificate" and "--kubelet-client-key" to an Approved Organizational Certificate and key pair.
Change to the /etc/kubernetes/manifests/ directory on the Kubernetes Master Node. Run the command:
grep -i kubelet-client-certificate *
grep -I kubelet-client-key *
If the setting "--kubelet-client-certificate" is not configured in the Kubernetes API server manifest file or contains no value, this is a finding.
If the setting "--kubelet-client-key" is not configured in the Kubernetes API server manifest file or contains no value, this is a finding.
V-242441
False
CNTR-K8-002640
Change to the /etc/kubernetes/manifests/ directory on the Kubernetes Master Node. Run the command:
grep -i kubelet-client-certificate *
grep -I kubelet-client-key *
If the setting "--kubelet-client-certificate" is not configured in the Kubernetes API server manifest file or contains no value, this is a finding.
If the setting "--kubelet-client-key" is not configured in the Kubernetes API server manifest file or contains no value, this is a finding.
M
5376