Ensure that the API Server only makes use of Strong Cryptographic Ciphers (Manual)
Quellsprache: Englisch
Menü
Skills in diesem Repository
SkillsMP hat 7.442 Skills aus CyberStrikeus/CyberStrike gesammelt. Öffne einen Skill, um Quelle und Details zu prüfen.
CyberStrikeus/CyberStrikeEs werden 40 von 7.442 gesammelten Skills angezeigt.
Ensure that the API Server only makes use of Strong Cryptographic Ciphers (Manual)
Quellsprache: Englisch
Ensure that unsupported configuration overrides are not used (Manual)
Quellsprache: Englisch
Use https for kubelet connections (Manual)
Quellsprache: Englisch
Ensure that the kubelet uses certificates to authenticate (Manual)
Quellsprache: Englisch
Verify that the kubelet certificate authority is set as appropriate (Manual)
Quellsprache: Englisch
Ensure that the --authorization-mode argument is not set to AlwaysAllow (Manual)
Quellsprache: Englisch
Verify that RBAC is enabled (Manual)
Quellsprache: Englisch
Ensure that the APIPriorityAndFairness feature gate is enabled (Manual)
Quellsprache: Englisch
Ensure controller manager healthz endpoints protected by RBAC (Manual)
Quellsprache: Englisch
Ensure --use-service-account-credentials set to true (Manual)
Quellsprache: Englisch
Ensure --service-account-private-key-file set (Manual)
Quellsprache: Englisch
Ensure --root-ca-file set as appropriate (Manual)
Quellsprache: Englisch
Ensure --bind-address set to 127.0.0.1 (Manual)
Quellsprache: Englisch
Ensure healthz endpoints for scheduler protected by RBAC (Manual)
Quellsprache: Englisch
Verify scheduler API service protected by RBAC (Manual)
Quellsprache: Englisch
Ensure --cert-file and --key-file set (Manual)
Quellsprache: Englisch
Ensure --client-cert-auth set to true (Manual)
Quellsprache: Englisch
Ensure --auto-tls not set to true (Manual)
Quellsprache: Englisch
Ensure --peer-cert-file and --peer-key-file set (Manual)
Quellsprache: Englisch
Ensure --peer-client-cert-auth set to true (Manual)
Quellsprache: Englisch
Ensure --peer-auto-tls not set to true (Manual)
Quellsprache: Englisch
Ensure unique Certificate Authority used for etcd (Manual)
Quellsprache: Englisch
Client certificate authentication should not be used for users (Manual)
Quellsprache: Englisch
Ensure minimal audit policy created (Manual)
Quellsprache: Englisch
Ensure audit policy covers key security concerns (Manual)
Quellsprache: Englisch
Ensure that the kubelet service file permissions are set to 644 or more restrictive (Automated)
Quellsprache: Englisch
Ensure that the kubelet configuration file ownership is set to root:root (Automated)
Quellsprache: Englisch
Ensure that the kubelet service file ownership is set to root:root (Automated)
Quellsprache: Englisch
If proxy kubeconfig file exists ensure permissions are set to 644 or more restrictive (Manual)
Quellsprache: Englisch
If proxy kubeconfig file exists ensure ownership is set to root:root (Manual)
Quellsprache: Englisch
Ensure that the --kubeconfig kubelet.conf file permissions are set to 644 or more restrictive (Automated)
Quellsprache: Englisch
Ensure that the --kubeconfig kubelet.conf file ownership is set to root:root (Automated)
Quellsprache: Englisch
Ensure that the certificate authorities file permissions are set to 644 or more restrictive (Automated)
Quellsprache: Englisch
Ensure that the client certificate authorities file ownership is set to root:root (Automated)
Quellsprache: Englisch
Ensure that the kubelet --config configuration file has permissions set to 600 or more restrictive (Automated)
Quellsprache: Englisch
Activate Garbage collection in OpenShift Container Platform 4, as appropriate (Manual)
Quellsprache: Englisch
Ensure that the --rotate-certificates argument is not set to false (Manual)
Quellsprache: Englisch
Verify that the RotateKubeletServerCertificate argument is set to true (Manual)
Quellsprache: Englisch
Ensure that the Kubelet only makes use of Strong Cryptographic Ciphers (Manual)
Quellsprache: Englisch
Ensure that the --anonymous-auth argument is set to false (Automated)
Quellsprache: Englisch