Uploaded image for project: 'Cloud Infrastructure Security & Compliance'
  1. Cloud Infrastructure Security & Compliance
  2. CMP-959

[AC-12]: check token max age configuration

XMLWordPrintable

    • 2
    • False
    • False
    • OCPPLAN-6104 - FedRAMP moderate controls
    • Undefined
    • CMP Sprint 31

      AC-12 describes mostly organizational triggers that disconnect a user, but in almost all discussions of the control we agreed that token max age should be set. Therefore we need a rule to check it!

      Acceptance critera:

      • create a rule with an OVAL check that tests that either of the following is true:
        • all of the oauthclient objects have the accessTokenMaxAgeSeconds attribute set
        • the oauth.cluster has .spec.tokenConfig.accessTokenMaxAgeSeconds attribute set
      • create an E2E test for the check{{}}

              jhrozek@redhat.com Jakub Hrozek (Inactive)
              jhrozek@redhat.com Jakub Hrozek (Inactive)
              Prashant Dhamdhere Prashant Dhamdhere (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: