7.6 Ensure that the swarm manager auto-lock key is rotated periodically

Information

You should rotate the swarm manager auto-lock key periodically.

Rationale:

The swarm manager auto-lock key is not automatically rotated. Good security practice is to rotate keys.

Impact:

None

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

You should run the command below to rotate the keys.

docker swarm unlock-key --rotate

Additionally, to facilitate auditing of this recommendation, you should maintain key rotation records and ensure that you establish a pre-defined frequency for key rotation.

Default Value:

By default, keys are not rotated automatically.

See Also

https://workbench.cisecurity.org/files/4532

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.4

Plugin: Unix

Control ID: 3903fdb3a417e25eb7bcd8ed7332f575d17604fb8c6f2c247890375fc754d4bc