5.6.7 Use Google managed SSL certificates for GKE Ingress TLS

Information

Use Google managed SSL certificates for GKE Ingress TLS to encrypt client traffic between external users and the Google Cloud load balancer. Google provisions and renews these certificates for the configured domains, reducing manual certificate lifecycle management for supported GKE Ingress use cases.

TLS encryption for GKE Ingress helps protect application traffic between clients and the load balancer by preventing plaintext exposure over external networks. Google managed SSL certificates reduce operational risk by having Google provision, manage, and automatically renew domain validated certificates for supported load balancer and Ingress configurations.

This control is most appropriate for HTTPS traffic exposed through GKE Ingress. It does not apply to TCP or UDP load balancers created through a Service of type LoadBalancer, and GKE Ingress does not support certificates managed by Certificate Manager. Use Gateway API if Certificate Manager managed certificates are required.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Remediate public HTTPS workloads by using GKE Ingress with Google managed SSL certificates where this pattern is appropriate. This applies to HTTPS traffic terminated by the external Application Load Balancer through GKE Ingress and does not apply to TCP or UDP workloads exposed through Service objects of type LoadBalancer.

-

For public HTTP or HTTPS workloads exposed directly through Service objects of type LoadBalancer, evaluate whether they should be exposed through GKE Ingress so Google managed SSL certificates can be used.

-

Create a ManagedCertificate object in the same namespace as the Ingress and define the approved non wildcard domain names for the certificate.

-

Update the Ingress metadata to include the networking.gke.io/managed-certificates annotation with the ManagedCertificate resource name. Multiple managed certificates can be listed as comma separated values when needed.

-

Confirm that DNS records for the certificate domains point to the load balancer IP address, because Google must validate domain ownership before the certificate becomes active.

-

After the certificate is active, verify that the Ingress serves HTTPS traffic using the Google managed certificate and remove any obsolete self managed certificate references that are no longer required.

Impact:

Google managed SSL certificates are less flexible than self managed certificates. They support up to 100 non wildcard domains, do not support wildcard domains, and cannot be updated in place to add or remove domains. DNS records must point to the load balancer for validation and renewal, and provisioning can remain pending until domain ownership and load balancer association are confirmed.

See Also

https://workbench.cisecurity.org/benchmarks/24956

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: GCP

Control ID: ee03ac68caa6a596dde76d25a2339bba750f5067bae8d77735e6c83aae58680b