7.3 Ensure that all Docker swarm overlay networks are encrypted

Information

Ensure that all Docker swarm overlay networks are encrypted.

Rationale:

By default, data exchanged between containers on nodes on the overlay network is not encrypted. This could potentially expose traffic between containers.

Impact:

None

Solution

You should create overlay networks the with --opt encrypted flag.

Default Value:

By default, data exchanged in overlay networks in Docker swarm mode is not encrypted.

See Also

https://workbench.cisecurity.org/files/4532

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: Unix

Control ID: 1ac10783e1eaf2fe60f30288fe6d3bd9f29f07bb568bb5dbe87b95a8bd39c17b