| name | cis-k8s-v200-4.1.8 |
| description | Ensure that the client certificate authorities file ownership is set to root:root (Manual) |
| category | cis-k8s |
| version | 2.0.0 |
| author | cyberstrike-official |
| tags | ["cis","kubernetes","worker-node","config-files","file-ownership","certificates"] |
| cis_id | 4.1.8 |
| cis_benchmark | CIS Kubernetes Benchmark v2.0.0 |
| tech_stack | ["kubernetes"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
4.1.8 Ensure that the client certificate authorities file ownership is set to root:root (Manual)
Profile Applicability
Description
Ensure that the certificate authorities file ownership is set to root:root.
Rationale
The certificate authorities file controls the authorities used to validate API requests. You should set its file ownership to maintain the integrity of the file. The file should be owned by root:root.
Impact
None
Audit
Run the following command:
ps -ef | grep kubelet
Find the file specified by the --client-ca-file argument.
Run the following command:
stat -c %U:%G <filename>
Verify that the ownership is set to root:root.
Remediation
Run the following command to modify the ownership of the --client-ca-file.
chown root:root <filename>
Default Value
By default no --client-ca-file is specified.
References
- https://kubernetes.io/docs/admin/authentication/#x509-client-certs
CIS Controls
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|
| v8 | 5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts - Restrict administrator privileges to dedicated administrator accounts on enterprise assets. Conduct general computing activities, such as internet browsing, email, and productivity suite use, from the user's primary, non-privileged account. | * | * | * |
| v7 | 4 Controlled Use of Administrative Privileges - Controlled Use of Administrative Privileges | | | |