1.2.7 Ensure that the --authorization-mode argument is not set to AlwaysAllow

Information

Do not always authorize all requests.

The API Server, can be configured to allow all requests. This mode should not be used on any production cluster.

Solution

None. RBAC is always on and the OpenShift API server does not use the values assigned to the flag authorization-mode.

Impact:

Only authorized requests will be served.

See Also

https://workbench.cisecurity.org/benchmarks/19464

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|9.2

Plugin: OpenShift

Control ID: 5cde70c67029277712afb1537fc288b81893508335bc84755a280bcd59bae6eb