UCF STIG Viewer Logo

The container platform must be built from verified packages.


Overview

Finding ID Version Rule ID IA Controls Severity
V-233064 SRG-APP-000131-CTR-000280 SV-233064r601695_rule Medium
Description
It is important to patch and upgrade the container platform when patches and upgrades are available. More important is to get these patches and upgrades from a known source. To validate the authenticity of any patches and upgrades before installation, the container platform must check that the files are digitally signed by sources approved by the organization.
STIG Date
Container Platform Security Requirements Guide 2021-12-14

Details

Check Text ( C-36000r601694_chk )
Review the container platform configuration to verify it has been built from packages that are digitally signed by known and approved sources.

If the container platform was built from packages that are not digitally signed or are from unknown or non-approved sources, this is a finding.
Fix Text (F-35968r600680_fix)
Rebuild the container platform from verified packages that are digitally signed by known and approved sources.