Skip to main content
CUI

Documentation - V-254566

V-254566

Rancher Government Solutions RKE2 Security Technical Implementation Guide

CAT II

Title

Rancher RKE2 runtime must enforce ports, protocols, and services that adhere to the PPSM CAL.

Description

<VulnDiscussion>Ports, protocols, and services within the RKE2 runtime must be controlled and conform to the PPSM CAL. Those ports, protocols, and services that fall outside the PPSM CAL must be blocked by the runtime. Instructions on the PPSM can be found in DOD Instruction 8551.01 Policy. RKE2 sets most ports and services configuration upon initiation; however, these ports can be changed after the fact to noncompliant configurations. It is important to verify core component configurations for...

Fix Text (Documentation Requirement)

Review the documentation covering how to set these PPSs and update this configuration file: /etc/rancher/rke2/config.yaml Once the configuration file is updated, restart the RKE2 Server. Run the command: systemctl restart rke2-server

Documentation Status

Cancel
CUI