3.1.3 Ensure that the --insecure-allow-any-token argument is not set

Information

Do not allow any insecure tokens.

Rationale:

Accepting insecure tokens would allow any token without actually authenticating anything. User information is parsed from the token and connections are allowed.

Solution

Edit the deployment specs and remove `--insecure-allow-any-token`. `kubectl edit deployments federation-apiserver-deployment --namespace=federation-system`

Impact:

None

See Also

https://workbench.cisecurity.org/files/1738

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2, CSCv6|16

Plugin: Unix

Control ID: fa3ecec7a1d7efd031a9cf8470830d7893e113b4ca183985e62fdc36d76e1548