7.6 Ensure that the swarm manager auto-lock key is rotated periodically

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

You should rotate the swarm manager auto-lock key periodically.

The swarm manager auto-lock key is not automatically rotated. Good security practice is to rotate keys.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

You should run the command below to rotate the keys.

docker swarm unlock-key --rotate

Additionally, to facilitate auditing of this recommendation, you should maintain key rotation records and ensure that you establish a pre-defined frequency for key rotation.

Impact:

None

See Also

https://workbench.cisecurity.org/benchmarks/16041