Skip to content

Commit fa777d4

Browse files
authored
Merge pull request #10615 from jhrozek/SRG-APP-000158-CTR-000390
SRG-APP-000158-CTR-000390: Add supporting evidence to an Inherently Met rule
2 parents f08027a + 1e5573d commit fa777d4

File tree

1 file changed

+9
-0
lines changed

1 file changed

+9
-0
lines changed

controls/srg_ctr/SRG-APP-000158-CTR-000390.yml

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,3 +5,12 @@ controls:
55
title: {{{ full_name }}} must uniquely identify all network-connected nodes
66
before establishing any connection.
77
status: inherently met
8+
artifact_description: |-
9+
Supporting evidence is in the following documentation
10+
https://docs.openshift.com/container-platform/latest/security/certificate_types_descriptions/node-certificates.html
11+
status_justification: |-
12+
Internal components are secured with two-way TLS.
13+
https://docs.openshift.com/container-platform/latest/security/certificate_types_descriptions/node-certificates.html
14+
Node certificates are signed by the cluster; they come from a certificate authority (CA) that is generated by the bootstrap process. Once the cluster is installed, the node certificates are auto-rotated.
15+
Node certificates are managed by the cluster and not the user
16+

0 commit comments

Comments
 (0)