DKER-EE-005080 - Docker Enterprise node certificates must be rotated as defined in the System Security Plan (SSP).

Information

Rotate swarm node certificates as appropriate.

Docker Swarm uses mutual TLS for clustering operations amongst its nodes. Certificate rotation ensures that in an event such as compromised node or key, it is difficult to impersonate a node. By default, node certificates are rotated every 90 days. The user should rotate it more often or as appropriate in their environment.

By default, node certificates are rotated automatically every 90 days.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Run the below command to set the desired expiry time.

Example:
docker swarm update --cert-expiry 48h

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Docker_Enterprise_2-x_Linux-Unix_V2R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-235850r961863_rule, STIG-ID|DKER-EE-005080, STIG-Legacy|SV-104873, STIG-Legacy|V-95735, Vuln-ID|V-235850

Plugin: Unix

Control ID: cab4640f386bb6bf4833ed2657f72e6043bd118487c5f8058a2dea111b82415e