EC CFB8 ..... 16
9.2.3 Usage of AES-GCM ..... 16
9.2.4 Usage of Triple-DES ..... 16
9.2.5 RSA and ECDSA Keys ..... 16
## 1 Introduction
This non-proprietary security policy for the Rancher Kubernetes Cryptographic V and Key values|User, CO|Write/Execute|
|Signature Generation/Verification|CTR\_DRBG, RSA, ECDSA|RSA, ECDSA private key|User, CO|Write/Execute|
|Key Transport|RSA|RSA private key|User, CO|Write/Execute| 0 码力 |
16 页 |
551.69 KB
| 2 年前 3 ue --bind-address=0.0.0.0 --tls-cipher-
suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 e --bind-address=0.0.0.0 --tls-
cipher-
suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA
_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY130
5,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 e --bind-address=0.0.0.0 --tls-
cipher-
suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA
_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY130
5,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 0 码力 |
132 页 |
1.12 MB
| 2 年前 3 vA".
The host key fingerprints are:
RSA SHA256:3IvYMkU05lQSKBxOVZUJMzdtXpz3RJl3dEQsg3UWc54 ECDSA SHA256:xd1xnkBpn49DUbuP8uWro2mu1GM4MtnqR2WEWglfS3o ED25519 SHA256:Hk3+/4+X7NJBHl6/e/6xFhNXsbHBsOvt6i8YEFUepko 111.24
The authenticity of host '10.222.111.24 (10.222.111.24)' can't be established.
ECDSA key fingerprint is
SHA256: xd1xnkBpn49DUbuP8uWro2mu1GM4MtnqR2WEWg1fS3o.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '10.222.111.24' (ECDSA) to the list of known hosts.
installer@10.222.111.24's password: KRuXtz5dURAyPkjcJcUvA
• One 0 码力 |
486 页 |
3.33 MB
| 1 年前 3 with long duration deployed on this server. MORE INFO »
## Certificate #1: EC 256 bits (SHA256 with ECDSA)

ECDSA_WITH_AES_128_CBC_SHA,
tls.TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA,
tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
tls.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 5,
// tls.TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,
tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
tls.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
0 码力 |
20 页 |
6.28 MB
| 2 年前 3 --feature-gates="RotateKubeletServerCertificate=true"
• --tls-cipher-suites="TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128"
## Remediation
• Add the following to the ertificate=true"
protect-kernel-defaults: "true"
tls-cipher-suites: "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128"
Where is in a form like --audit-log-format=json
--audit-policy-file=/etc/kubernetes/audit-policy.yaml
--tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
• In the volume section of the output 0 码力 |
44 页 |
279.78 KB
| 2 年前 3 lts: "true"
tls-cipher-suites: "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA 256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_128_GCM_SHA256"
extra_binds: []
extra_env: []
cluster_domain: streaming-connection-idle-timeout: 1800s
tls-cipher-suites: >-
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 0 码力 |
21 页 |
191.56 KB
| 2 年前 3 s: "true"
tls-cipher-suites: "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 84,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_128_GCM_SHA256"
extra_binds: []
extra_env: []
cluster_domain: le-timeout: 1800s
tls-cipher-suites: >-
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 0 码力 |
22 页 |
197.27 KB
| 2 年前 3 kube-apiserver | jq -e '.[0].Args[] | match("--tls-cipher-suites=.*)
Returned Value: TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
docker inspect kube-apiserver | jq -e '.[0].Args[] | match("--tls-cipher-suites= kube-apiserver | jq -e '.[0].Args[] | match("--tls-cipher-suites=.*)
Returned Value: TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305
docker inspect kube-apiserver | jq -e '.[0].Args[] | match("--tls-cipher-suites= kube-apiserver | jq -e '.[0].Args[] | match("--tls-cipher-suites=.*)
Returned Value: TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
docker inspect kube-apiserver | jq -e '.[0].Args[] | match("--tls-cipher-suites= 0 码力 |
47 页 |
302.56 KB
| 2 年前 3 ,求数n
|Bits of security|Symmetric key algorithms|FFC (e.g., DSA, D-H)|IFC (e.g., RSA)|ECC (e.g., ECDSA)|
|---|---|---|---|---|
|80|2TDEA $ ^{18} $|L = 1024N = 160|k = 1024|f = 160-223|
|112|3TDEA|L = 2048N >✓ | ✓ | ✓ | ✓ | ✓ | | ✓ | | | | ECDSA | ✓ | | ✓ | ✓ | ✓ | ✓ | ✓ | | ✓ | < >✓ | ✓ | ✓ | ✓ | ✓ | | ✓ | | | | ECDSA | ✓ | | ✓ | ✓ | ✓ | ✓ | ✓ | | ✓ | < 0 码力 |
44 页 |
3.70 MB
| 2 年前 3
|
|