cis-ocp-v160-3.1.1
Client certificate authentication should not be used for users (Manual)
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Client certificate authentication should not be used for users (Manual)
Ensure that a minimal audit policy is created (Manual)
Ensure that the kubelet service file permissions are set to 644 or more restrictive (Automated)
Ensure that the kubelet configuration file ownership is set to root:root (Automated)
Ensure that the kubelet service file ownership is set to root:root (Automated)
Ensure that the --kubeconfig kubelet.conf file ownership is set to root:root (Automated)
Ensure that the client certificate authorities file ownership is set to root:root (Automated)
Activate Garbage collection in OpenShift Container Platform 4, as appropriate (Manual)
Ensure that the --rotate-certificates argument is not set to false (Manual)
Verify that the RotateKubeletServerCertificate argument is set to true (Manual)