SV-242449r712703_rule
V-242449
SRG-APP-000516-CTR-001325
CNTR-K8-003160
CAT II
10
Change the permissions of the --client-ca-file to "644" by executing the command:
chown 644 <kubelet --client--ca-file argument location>.
Change to the /etc/sysconfig/ directory on the Kubernetes Master Node. Run command:
more kubelet
--client-ca-file argument
Note certificate location
If the ca-file argument location file has permissions more permissive than "644", this is a finding.
V-242449
False
CNTR-K8-003160
Change to the /etc/sysconfig/ directory on the Kubernetes Master Node. Run command:
more kubelet
--client-ca-file argument
Note certificate location
If the ca-file argument location file has permissions more permissive than "644", this is a finding.
M
5376