Back

Configure the "rotate-certificates" argument to organizational standards.


CONTROL ID
14640
CONTROL TYPE
Configuration
CLASSIFICATION
Preventive

SUPPORTING AND SUPPORTED CONTROLS




This Control directly supports the implied Control(s):
  • Configure "Kubernetes" to organizational standards., CC ID: 14528

There are no implementation support Controls.


SELECTED AUTHORITY DOCUMENTS COMPLIED WITH




  • Ensure that the --rotate-certificates argument is not set to false Description: Enable kubelet client certificate rotation. Rationale: The --rotate-certificates setting causes the kubelet to rotate its client certificates by creating new CSRs as its existing credentials expire. This automated period… (4.2.11, The Center for Internet Security Kubernetes Level 1 Worker Node Benchmark, v 1.6.0)
  • Ensure that the --rotate-certificates argument is not set to false Description: Enable kubelet client certificate rotation. Rationale: The --rotate-certificates setting causes the kubelet to rotate its client certificates by creating new CSRs as its existing credentials expire. This automated period… (4.2.11, The Center for Internet Security Kubernetes Level 2 Worker Node Benchmark, v 1.6.0)