7.9 Ensure CA certificates are rotated as appropriate

Information

Rotate root CA certificates as appropriate.
Rationale:
Docker Swarm uses mutual TLS for clustering operations amongst its nodes. Certificate rotation ensures that in an event such as compromised node or key, it is difficult to impersonate a node. Node certificates depend upon root CA certificates. For operational security, it is important to rotate these frequently. Currently, root CA certificates are not rotated automatically. You should thus establish a process to rotate it at the desired frequency.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Run the below command to rotate the certificate.
docker swarm ca --rotate
Impact:
None
Default Value:
By default, root CA certificates are not rotated.

See Also

https://workbench.cisecurity.org/files/1726

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(2), CSCv6|14.2

Plugin: Unix

Control ID: b65ddfd03ff4e245efcf909afcddff6509367da860ca682e84e01de42f3309ac