Uploaded image for project: 'Cloud Infrastructure Security & Compliance'
  1. Cloud Infrastructure Security & Compliance
  2. CMP-973

[AU-9]: When logs are forwarded, make sure TLS is used

XMLWordPrintable

    • 1
    • False
    • False
    • OCPPLAN-6104 - FedRAMP moderate controls
    • Undefined
    • CMP Sprint 32

      Per https://docs.openshift.com/container-platform/4.6/logging/cluster-logging-external.html the ClusterLogForwarder output attributes define the protocol used. To satisfy integrity of audit logs in transit, we must make sure that the outputs use TLS.

      Looking at the docs, it should be enough to create a rule that ensures that either the https:// or the tls:// protocols are used.

            josorior@redhat.com Juan Antonio Osorio (Inactive)
            jhrozek@redhat.com Jakub Hrozek
            Prashant Dhamdhere Prashant Dhamdhere (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: