1.2.2 Ensure that the --basic-auth-file argument is not set - ClusterOperators

Information

Do not use basic authentication.

Rationale:

Basic authentication uses plaintext credentials for authentication. Currently, the basic authentication credentials last indefinitely, and the password cannot be changed without restarting the API server. The basic authentication is currently supported for convenience. Hence, basic authentication should not be used.

Impact:

OpenShift uses tokens and certificates for authentication.

Solution

None required. --basic-auth-file cannot be configured on OpenShift.

Default Value:

By default, --basic-auth-file argument is not set and OAuth authentication is configured.

See Also

https://workbench.cisecurity.org/benchmarks/14166

Item Details

Category: CONFIGURATION MANAGEMENT, MAINTENANCE

References: 800-53|CM-7, 800-53|MA-4, CSCv7|16.4

Plugin: OpenShift

Control ID: 99ac39559cd133084cd7738d2bf14bf1355fcef2f8de06a2fd9befbe7e439d39