7.4 Ensure that all Docker swarm overlay networks are encrypted

Information

Ensure that all Docker swarm overlay networks are encrypted.

Rationale:

By default, data exchanged between containers on nodes on the overlay network is not encrypted. This could potentially expose traffic between containers.

Solution

You should create overlay networks the with --opt encrypted flag.

Impact:

None

Default Value:

By default, data exchanged in overlay networks in Docker swarm mode is not encrypted.

See Also

https://workbench.cisecurity.org/files/2433

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CSCv6|14.2, CSCv7|14.4

Plugin: Unix

Control ID: ffa24df38cfe2906533bea2ec580bf1ae47b81dcbfbd78951e57302ac61e9c99