3.17 Verify that registry certificate file ownership is set to root:root

Information

Verify that all the registry certificate files (usually found
under /etc/docker/certs.d/<registry-name> directory) are owned and group-owned by
'root'.

/etc/docker/certs.d/<registry-name> directory contains Docker registry certificates.
These certificate files must be owned and group-owned by 'root' to maintain the integrity
of the certificates.

See Also

https://workbench.cisecurity.org/files/514

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|3.1

Plugin: Unix

Control ID: 0feb39c409fde184ccf8f0175d78afb8b073c3ed2e3e19c2cff9c2563a2bd077