Skip to content

Commit

Permalink
SRG-APP-000158-CTR-000390: Add supporting evidence to an Inherently M…
Browse files Browse the repository at this point in the history
…et rule
  • Loading branch information
jhrozek committed May 23, 2023
1 parent 91ba1a5 commit a2cee70
Showing 1 changed file with 8 additions and 0 deletions.
8 changes: 8 additions & 0 deletions controls/srg_ctr/SRG-APP-000158-CTR-000390.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,3 +5,11 @@ controls:
title: {{{ full_name }}} must uniquely identify all network-connected nodes
before establishing any connection.
status: inherently met
artifact_description: |-
Supporting evidence is in the following documentation
https://docs.openshift.com/container-platform/latest/security/certificate_types_descriptions/node-certificates.html
status_justification: |-
Internal components are secured with two-way TLS.
https://docs.openshift.com/container-platform/latest/security/certificate_types_descriptions/node-certificates.html
Node certificates are signed by the cluster; they come from a certificate authority (CA) that is generated by the bootstrap process. Once the cluster is installed, the node certificates are auto-rotated.
Node certificates are managed by the cluster and not the user

0 comments on commit a2cee70

Please sign in to comment.