CIS Kubernetes Benchmark v1.10.0 - 1.2.29

1 votes

In 1.2.29 Ensure that the API Server only makes use of Strong Cryptographic Ciphers the benchmark recommends to use some insecure ciphers.

Please compare with
https://kubernetes.io/docs/reference/command-line-tools-reference/kube-apiserver/
parameter --tls-cipher-suites - Insecure values

Also compare with
https://github.com/ssllabs/research/wiki/SSL-and-TLS-Deployment-Best-Practices#23-use-secure-cipher-suites
64-bit block cipher (3DES / DES / RC2 / IDEA) are weak.

Done Benchmark Community Suggestion Suggested by: Vitali Henrichs Upvoted: 16 May, '24 Comments: 1

Comments: 1
OldestNewestMost likesFewest likes