Skip to content

Rancher Government Solutions RKE2 Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Rancher RKE2 must store only cryptographic representations of passwords.

    <VulnDiscussion>Secrets, such as passwords, keys, tokens, and certificates should not be stored as environment variables. These environment v...
    Rule Medium Severity
  • SRG-APP-000190-CTR-000500

    <GroupDescription></GroupDescription>
    Group
  • SRG-APP-000014-CTR-000035

    <GroupDescription></GroupDescription>
    Group
  • Rancher RKE2 must protect authenticity of communications sessions with the use of FIPS-validated 140-2 or 140-3 security requirements for cryptographic modules.

    &lt;VulnDiscussion&gt;Use strong TLS settings. RKE2 uses FIPS validated BoringCrypto modules. RKE2 Server can prohibit the use of SSL and unauthor...
    Rule High Severity
  • SRG-APP-000023-CTR-000055

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules