3.1.6 Ensure that the --secure-port argument is not set to 0

Information

Do not disable the secure port.

Rationale:

The secure port is used to serve https with authentication and authorization. If you disable it, no https traffic is served and all traffic is served unencrypted.

Solution

Edit the deployment specs and set the `--secure-port` argument to the desired port. `kubectl edit deployments federation-apiserver-deployment --namespace=federation-system`

Impact:

You need to set the federation apiserver up with the right TLS certificates.

See Also

https://workbench.cisecurity.org/files/1738

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8(1), CSCv6|14.2

Plugin: Unix

Control ID: 8a6945cd8a67acebe7a56f4a8171fdd28f31c7ad155541be23d2ac5f1aeaa57b