|
|
|
@ -388,7 +388,7 @@ groups:
|
|
|
|
|
scored: false
|
|
|
|
|
|
|
|
|
|
- id: 4.2.11
|
|
|
|
|
text: "Ensure that the --rotate-certificates argument is not set to false (Manual)"
|
|
|
|
|
text: "Ensure that the --rotate-certificates argument is not set to false (Automated)"
|
|
|
|
|
audit: "/bin/ps -fC $kubeletbin"
|
|
|
|
|
audit_config: "/bin/cat $kubeletconf"
|
|
|
|
|
tests:
|
|
|
|
@ -412,7 +412,7 @@ groups:
|
|
|
|
|
Based on your system, restart the kubelet service. For example:
|
|
|
|
|
systemctl daemon-reload
|
|
|
|
|
systemctl restart kubelet.service
|
|
|
|
|
scored: false
|
|
|
|
|
scored: true
|
|
|
|
|
|
|
|
|
|
- id: 4.2.12
|
|
|
|
|
text: "Verify that the RotateKubeletServerCertificate argument is set to true (Manual)"
|
|
|
|
|