3.9 Verify that TLS CA certificate file ownership is set to root:root

Information

Verify that the TLS CAcertificate file (the file that is passed alongwith '--tlscacert'parameter) is owned and group-owned by 'root'.

Rationale:

The TLS CA certificate file should be protected from any tampering. It is used to authenticate Docker server based on given CA certificate. Hence, itmust be owned and group-owned by 'root' to maintain the integrity of the CA certificate.

Solution

chown root:root <path to TLS CA certificate file>



This would set the ownership and group-ownership for the TLS CA certificate file to 'root'.

Impact:

None.

Default Value:

By default, the ownership and group-ownership for TLS CA certificate file is correctly set to 'root'.

See Also

https://workbench.cisecurity.org/files/1476

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Unix

Control ID: b31cd28d5b416198a6d6123ecb6c135dd8ff18dcd223d3e5b8c5fa1fc036b685