| name | cis-eks-v170-3.2.3 |
| description | Ensure that a Client CA File is Configured (Automated) |
| category | cis-eks |
| version | 1.7.0 |
| author | cyberstrike-official |
| tags | ["cis","eks","kubernetes","aws","worker-node","kubelet","authentication","tls","certificates"] |
| cis_id | 3.2.3 |
| cis_benchmark | CIS Amazon Elastic Kubernetes Service (EKS) Benchmark v1.7.0 |
| tech_stack | ["kubernetes","aws","eks"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
3.2.3 Ensure that a Client CA File is Configured (Automated)
Profile Applicability
Description
Enable Kubelet authentication using certificates.
Rationale
The connections from the apiserver to the kubelet are used for fetching logs for pods, attaching (through kubectl) to running pods, and using the kubelet's port-forwarding functionality. These connections terminate at the kubelet's HTTPS endpoint. By default, the apiserver does not verify the kubelet's serving certificate, which makes the connection subject to man-in-the-middle attacks, and unsafe to run over untrusted and/or public networks. Enabling Kubelet certificate authentication ensures that the apiserver could authenticate the Kubelet before submitting any requests.
You require TLS to be configured on apiserver as well as kubelets.
Audit Procedure
Audit Method 1:
Kubelets can accept configuration via a configuration file and in some cases via command line arguments. It is important to note that parameters provided as command line arguments will override their counterpart parameters in the configuration file (see --config details in the Kubelet CLI Reference for more info).
With this in mind, it is important to check for the existence of command line arguments as well as configuration file entries when auditing Kubelet configuration.
Firstly, SSH to each node and execute the following command to find the Kubelet process:
ps -ef | grep kubelet
The output of the above command provides details of the active Kubelet process, from which we can see the command line arguments provided to the process. Also note the location of the configuration file, provided with the --config argument, as this will be needed to verify configuration. The file can be viewed with a command such as more or less, like so:
sudo less /path/to/kubelet-config.json
Verify that a client certificate authority file is configured. This may be configured using a command line argument to the kubelet service with --client-ca-file or in the kubelet configuration file via "authentication": { "x509": {"clientCAFile": <path/to/client-ca-file> } }.
Audit Method 2:
It is also possible to review the running configuration of a Kubelet via the /configz endpoint of the Kubernetes API. This can be achieved using kubectl to proxy your requests to the API.
Discover all nodes in your cluster by running the following command: