1.2.3 Ensure that the --token-auth-file parameter is not set

Information

Do not use token based authentication.

The token-based authentication utilizes static tokens to authenticate requests to the apiserver The tokens are stored in clear-text in a file on the apiserver and cannot be revoked or rotated without restarting the apiserver Hence, do not use static token-based authentication.

Solution

None is required.

Impact:

OpenShift does not use the token-auth-file flag. OpenShift includes a built-in OAuth server rather than relying on a static token file. The OAuth server is integrated with the API server.

See Also

https://workbench.cisecurity.org/benchmarks/19464

Item Details

Category: CONFIGURATION MANAGEMENT, MAINTENANCE

References: 800-53|CM-7, 800-53|MA-4, CSCv7|16.4

Plugin: OpenShift

Control ID: 16ceced8fb7f756d620b1f1e60c31d07298a2f2e81df1f6f84f45c2e67c94597