CNTR-R2-000460 Rancher RKE2 must be built from verified packages.

Information

Only RKE2 images that have been properly signed by Rancher Government's authorized key will be deployed to ensure the cluster's security and compliance with organizational policies.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Immediate action must be taken to remove non-verifiable images from the cluster and replace them with verifiable images.

Utilize Hauler (https://hauler.dev) to pull and verify RKE2 images from Rancher Government Solutions Carbide Repository.

For more information about pulling Carbide images and their signatures, including RKE2, see:
https://rancherfederal.github.io/carbide-docs/docs/registry-docs/downloading-images

See Also

https://workbench.cisecurity.org/benchmarks/0

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-5(3), CAT|II, CCI|CCI-001749, Rule-ID|SV-268321r1017019_rule, STIG-ID|CNTR-R2-000460, Vuln-ID|V-268321

Plugin: Unix

Control ID: bca37de7adfb133c1f6d7977bad82668ec0f133ea62531e26925f0840e7d3663