Uploaded image for project: 'Cloud Infrastructure Security & Compliance'
  1. Cloud Infrastructure Security & Compliance
  2. CMP-959

[AC-12]: check token max age configuration

XMLWordPrintable

    • 2
    • False
    • False
    • OCPPLAN-6104 - FedRAMP moderate controls
    • Undefined
    • CMP Sprint 31

      AC-12 describes mostly organizational triggers that disconnect a user, but in almost all discussions of the control we agreed that token max age should be set. Therefore we need a rule to check it!

      Acceptance critera:

      • create a rule with an OVAL check that tests that either of the following is true:
        • all of the oauthclient objects have the accessTokenMaxAgeSeconds attribute set
        • the oauth.cluster has .spec.tokenConfig.accessTokenMaxAgeSeconds attribute set
      • create an E2E test for the check{{}}

            jhrozek@redhat.com Jakub Hrozek
            jhrozek@redhat.com Jakub Hrozek
            Prashant Dhamdhere Prashant Dhamdhere (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: