UCF STIG Viewer Logo

Kubernetes API Server must disable token authentication to protect information in transit.


Overview

Finding ID Version Rule ID IA Controls Severity
V-245543 CNTR-K8-002630 SV-245543r864034_rule Medium
Description
Kubernetes token authentication uses password known as secrets in a plaintext file. This file contains sensitive information such as token, username and user uid. This token is used by service accounts within pods to authenticate with the API Server. This information is very valuable for attackers with malicious intent if the service account is privileged having access to the token. With this token a threat actor can impersonate the service account gaining access to the Rest API service.
STIG Date
Kubernetes Security Technical Implementation Guide 2022-12-02

Details

Check Text ( C-48818r863946_chk )
Change to the /etc/kubernetes/manifests/ directory on the Kubernetes Control Plane. Run the command:
grep -i token-auth-file *

If "token-auth-file" is set in the Kubernetes API server manifest file, this is a finding.
Fix Text (F-48773r863947_fix)
Edit the Kubernetes API Server manifest file in the /etc/kubernetes/manifests directory on the Kubernetes Control Plane. Remove parameter "--token-auth-file".