{
    "control": "SC-23",
    "title": "Session Authenticity",
    "ccis": [
        {
            "cci": "CCI-001184",
            "definition": "Protect the authenticity of communications sessions."
        },
        {
            "cci": "CCI-001185",
            "definition": "Invalidate session identifiers upon user logout or other session termination."
        },
        {
            "cci": "CCI-001188",
            "definition": "Generate a unique session identifier for each session with organization-defined randomness requirements."
        },
        {
            "cci": "CCI-001189",
            "definition": "Defines randomness requirements for generating unique session identifiers."
        },
        {
            "cci": "CCI-001664",
            "definition": "Recognize only session identifiers that are system-generated."
        },
        {
            "cci": "CCI-002469",
            "definition": "Defines the certificate authorities allowed to be used for verification of the establishment of protected sessions."
        },
        {
            "cci": "CCI-002470",
            "definition": "Only allow the use of organization-defined certificate authorities for verification of the establishment of protected sessions."
        }
    ],
    "rules_mapped": 27,
    "rules": [
        {
            "rule": "V-242418",
            "stig_id": "CNTR-K8-001400",
            "title": "The Kubernetes API server must use approved cipher suites.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-001184"
            ]
        },
        {
            "rule": "V-242419",
            "stig_id": "CNTR-K8-001410",
            "title": "Kubernetes API Server must have the SSL Certificate Authority set.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-001184"
            ]
        },
        {
            "rule": "V-242420",
            "stig_id": "CNTR-K8-001420",
            "title": "Kubernetes Kubelet must have the SSL Certificate Authority set.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-001184"
            ]
        },
        {
            "rule": "V-242421",
            "stig_id": "CNTR-K8-001430",
            "title": "Kubernetes Controller Manager must have the SSL Certificate Authority set.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-001184"
            ]
        },
        {
            "rule": "V-242422",
            "stig_id": "CNTR-K8-001440",
            "title": "Kubernetes API Server must have a certificate for communication.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-001184"
            ]
        },
        {
            "rule": "V-242423",
            "stig_id": "CNTR-K8-001450",
            "title": "Kubernetes etcd must enable client authentication to secure service.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-001184"
            ]
        },
        {
            "rule": "V-242424",
            "stig_id": "CNTR-K8-001460",
            "title": "Kubernetes Kubelet must enable tlsPrivateKeyFile for client authentication to secure service.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-001184"
            ]
        },
        {
            "rule": "V-242425",
            "stig_id": "CNTR-K8-001470",
            "title": "Kubernetes Kubelet must enable tlsCertFile for client authentication to secure service.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-001184"
            ]
        },
        {
            "rule": "V-242426",
            "stig_id": "CNTR-K8-001480",
            "title": "Kubernetes etcd must enable client authentication to secure service.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-001184"
            ]
        },
        {
            "rule": "V-242427",
            "stig_id": "CNTR-K8-001490",
            "title": "Kubernetes etcd must have a key file for secure communication.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-001184"
            ]
        },
        {
            "rule": "V-242428",
            "stig_id": "CNTR-K8-001500",
            "title": "Kubernetes etcd must have a certificate for communication.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-001184"
            ]
        },
        {
            "rule": "V-242429",
            "stig_id": "CNTR-K8-001510",
            "title": "Kubernetes etcd must have the SSL Certificate Authority set.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-001184"
            ]
        },
        {
            "rule": "V-242430",
            "stig_id": "CNTR-K8-001520",
            "title": "Kubernetes etcd must have a certificate for communication.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-001184"
            ]
        },
        {
            "rule": "V-242431",
            "stig_id": "CNTR-K8-001530",
            "title": "Kubernetes etcd must have a key file for secure communication.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-001184"
            ]
        },
        {
            "rule": "V-242432",
            "stig_id": "CNTR-K8-001540",
            "title": "Kubernetes etcd must have peer-cert-file set for secure communication.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-001184"
            ]
        },
        {
            "rule": "V-242433",
            "stig_id": "CNTR-K8-001550",
            "title": "Kubernetes etcd must have a peer-key-file set for secure communication.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-001184"
            ]
        },
        {
            "rule": "V-220903",
            "stig_id": "WN10-PK-000005",
            "title": "The DoD Root CA certificates must be installed in the Trusted Root Store.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000185",
                "CCI-002470"
            ]
        },
        {
            "rule": "V-220905",
            "stig_id": "WN10-PK-000015",
            "title": "The DoD Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000185",
                "CCI-002470"
            ]
        },
        {
            "rule": "V-220906",
            "stig_id": "WN10-PK-000020",
            "title": "The US DOD CCEB Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000185",
                "CCI-002470"
            ]
        },
        {
            "rule": "V-253429",
            "stig_id": "WN11-PK-000015",
            "title": "The DoD Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002470"
            ]
        },
        {
            "rule": "V-253430",
            "stig_id": "WN11-PK-000020",
            "title": "The US DOD CCEB Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002470"
            ]
        },
        {
            "rule": "V-205648",
            "stig_id": "WN19-PK-000010",
            "title": "Windows Server 2019 must have the DoD Root Certificate Authority (CA) certificates installed in the Trusted Root Store.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000185",
                "CCI-002470"
            ]
        },
        {
            "rule": "V-205649",
            "stig_id": "WN19-PK-000020",
            "title": "Windows Server 2019 must have the DoD Interoperability Root Certificate Authority (CA) cross-certificates installed in the Untrusted Certificates Store on unclassified systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000185",
                "CCI-002470"
            ]
        },
        {
            "rule": "V-205650",
            "stig_id": "WN19-PK-000030",
            "title": "Windows Server 2019 must have the US DoD CCEB Interoperability Root CA cross-certificates in the Untrusted Certificates Store on unclassified systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000185",
                "CCI-002470"
            ]
        },
        {
            "rule": "V-254442",
            "stig_id": "WN22-PK-000010",
            "title": "Windows Server 2022 must have the DoD Root Certificate Authority (CA) certificates installed in the Trusted Root Store.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000185",
                "CCI-002470"
            ]
        },
        {
            "rule": "V-254443",
            "stig_id": "WN22-PK-000020",
            "title": "Windows Server 2022 must have the DoD Interoperability Root Certificate Authority (CA) cross-certificates installed in the Untrusted Certificates Store on unclassified systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000185",
                "CCI-002470"
            ]
        },
        {
            "rule": "V-254444",
            "stig_id": "WN22-PK-000030",
            "title": "Windows Server 2022 must have the US DOD CCEB Interoperability Root CA cross-certificates in the Untrusted Certificates Store on unclassified systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000185",
                "CCI-002470"
            ]
        }
    ]
}