Rancher Kubernetes Cryptographic Library
FIPS 140-2 Non-Proprietary Security Policyreproduced and distributed in its entirety without modification. Rancher Kubernetes Cryptographic Library FIPS 140-2 Non-Proprietary Security Policy Document Version 1.1 January Policy Rancher Kubernetes Cryptographic Library Page 2 of 16 References Ref Full Specification Name Date [140] FIPS 140-2, Security Requirements for Cryptographic Modules 12/3/2002 [140AA] Derived Test Requirements 1/4/2011 [140IG] Implementation Guidance for FIPS 140-2 and the Cryptographic Module Validation Program 8/28/2020 [SP 800-38A] NIST SP 800-38A, Recommendation for Block0 码力 | 16 页 | 551.69 KB | 1 年前3
CIS 1.6 Benchmark - Self-Assessment Guide - Rancher v2.5.4appropriately configured (Automated) 1.2.35 Ensure that the API Server only makes use of Strong Cryptographic Ciphers (Automated) 1.3 Controller Manager 1.3.1 Ensure that the --terminated-pod-gc-threshold argument is set to true (Automated) 4.2.13 Ensure that the Kubelet only makes use of Strong Cryptographic Ciphers (Automated) 5.1 RBAC and Service Accounts 5.1.1 Ensure that the cluster-admin role is Returned Value: - aescbc: true 1.2.35 Ensure that the API Server only makes use of Strong Cryptographic Ciphers (Automated) Result: warn Remediation: Edit the API server pod specification file /etc/0 码力 | 132 页 | 1.12 MB | 1 年前3
Rancher CIS Kubernetes v.1.4.0 Benchmark Self
Assessmentssl/kube-ca.pem Result: Pass 1.1.30 - Ensure that the API Server only makes use of strong cryptographic ciphers (Not Scored) Audit (Allowed Ciphers) docker inspect kube-apiserver | jq -e '.[0].Args[] RotateKubeletServerCertificate=true Result: Pass 2.1.14 - Ensure that the kubelet only makes use of strong cryptographic ciphers (Not Scored) Audit (Allowed Ciphers) docker inspect kubelet | jq -e '.[0].Args[] |0 码力 | 47 页 | 302.56 KB | 1 年前3
Cloud Native Contrail Networking
Installation and Life Cycle ManagementGuide for Rancher RKE2
Update grub and reboot: sudo update-grub sudo reboot 3. Load the poll mode driver (PMD) kernel module according to the capabilities of your NIC. • If your NIC supports VFIO, then you might not need uio_pci_generic. If you see a Module uio_pci_generic not found error, then install the module first (for example: sudo apt install linux-modules-extra-5.4.0-xx-generic) before loading the module. 67 Juniper CN20 码力 | 72 页 | 1.01 MB | 1 年前3
SUSE Rancher and RKE Kubernetes cluster
using CSI Driver on DELL EMC PowerFlex s/tools/install-kubectl/ Docker 19.03.1 5 Docker is installed on each SLES node. #SUSEConnect -p sle- module- containers/15.2/x86_64 #zypper install docker SLES15 SP2 nodes SLES15 SP2 Ensure that the run the zypper update. 1. Run the following command to activate the containers module: $ SUSEConnect -p sle-module-containers/15.2/x86_64 2. Run the following commands to Install the docker, enable0 码力 | 45 页 | 3.07 MB | 1 年前3
Secrets Management at
Scale with Vault & RancherMulti-platform and multi-cloud ● Central control and management ● Auditing ● Compliance & Hardware Security Module (HSM) integration ● Costs, scalability & productivity HashiCorp Vault Provides the foundation0 码力 | 36 页 | 1.19 MB | 1 年前3
共 6 条
- 1













