3.8 Verify that registry certificate file permissions are set to 444 or more restrictive

Information

https://docs.docker.com/articles/certificates/
2.http://docs.docker.com/reference/commandline/cli/#insecure-registries

Solution

chmod 444 /etc/docker/certs.d/<registry-name>/*This would set the permissions for registry certificate files to '444'.
Impact-
None.
Default Value-
By default, the permissions for registry certificate files might not be '444'. The default file permissions are governed by the system or user specific umask values.

See Also

https://workbench.cisecurity.org/files/516

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Unix

Control ID: 5b17bf832e06834c9f547133cbed4b418a5fcf9d8dcf012e899aa97c6cbdb8ce