7.4 Ensure that all Docker swarm overlay networks are encrypted

Information

Ensure that all Docker swarm overlay networks are encrypted.

Rationale:

By default, data exchanged between containers on nodes on the overlay network is not encrypted. This could potentially expose traffic between containers.

Solution

You should create overlay networks the with --opt encrypted flag.

Impact:

None

Default Value:

By default, data exchanged in overlay networks in Docker swarm mode is not encrypted.

See Also

https://workbench.cisecurity.org/files/2433

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CSCv6|14.2, CSCv7|14.4

Plugin: Unix

Control ID: 76c9a445e5d61432c96a5307ffa8dba58aebb8439ef7ca742c578f66227c833f