DKER-EE-006240 - Docker Enterprise data exchanged between Linux containers on different nodes must be encrypted on the overlay network.

Information

Encrypt data exchanged between containers on different nodes on the overlay network.

By default, data exchanged between containers on different nodes on the overlay network is not encrypted. This could potentially expose traffic between the container nodes.

Solution

Create overlay network with --opt encrypted flag.

Example:
docker network create --opt encrypted --driver overlay my-network

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Docker_Enterprise_2-x_Linux-UNIX_V1R1_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|IA-5(2), 800-53|SC-13, CAT|II, CCI|CCI-002450, Rule-ID|SV-104919r1_rule, STIG-ID|DKER-EE-006240, Vuln-ID|V-95781

Plugin: Unix

Control ID: 329a77a93630892d836f96aa343f3a043429d6f5486b24383dab097e6121cb7f