Skip to main content

More Info:

The kubelet —client-ca-file should point to a client CA file so that certificate-based client authentication is enforced. Without it, clients cannot be verified via x509 certificates.

Risk Level

High

Address

Security

Compliance Standards

  • CIS AKS

Triage and Remediation

Remediation

Using Console

Refer to the remediation guidance for this control. Detailed console, CLI and Python steps are being generated.