4213-k8s-kubelet-tls-cipher-suites-Ensure Kubelet Is Configured to Use Only Strong Encryption Ciphers¶
Rule ID¶
- 4213-k8s-kubelet-tls-cipher-suites
Category¶
- container
Level¶
- info
Compatible Versions¶
- Linux
Description¶
- Ensure Kubelet is configured to use only strong encryption ciphers
Scan Frequency¶
- 0 */30 * * *
Rationale¶
- TLS ciphers have many known vulnerabilities and weaknesses, making such protection less secure. Kubernetes itself supports many types of encryption methods and cipher suites, which can strengthen program security.
Risk Items¶
- Container Security
Audit Method¶
- Run the following command to verify:
Remediation¶
- The kubelet version must not be lower than v1.16.0.
Execute the following command: Set or add the parameter--tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_128_GCM_SHA256
If started via a configuration file, check the kubelet startup parameter-configand modify thetls-cipher-suitesin the file:
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_128_GCM_SHA256
After setting, restart the service:
Impact¶
- Kubelet clients that do not support modern encryption ciphers will be unable to connect to the Kubelet API.
Default Value¶
- By default, the Kubernetes API server supports a wide range of TLS ciphers.
References¶
CIS Controls¶
- None