cis-operator
cis-operator copied to clipboard
Review `tls-cipher-suites` rules and documentation
k3s and rke2 have stronger default settings which by default already comply with CIS Benchmark recommendations. However, at times it is not clear to the end user that this is the case:
The rule description does not seem to align with the documentation:
Remediation: By default, RKE2 explicitly doesn't set this flag. No manual remediation needed.
This issue tracks the improvement of both documentation and rules to make them clearer to end users.
cc @andypitcher
The documentation update for the related checks will be handled in https://github.com/rancher/rancher/issues/45318. I'm Closing this issues.