Description
masterAuth.clientCertificateConfig.issueClientCertificate controls issuance of a legacy GKE client certificate. Google discourages this authentication method. Setting it to false does not disable cluster authentication or server TLS.
Use recommended Google Cloud authentication with the required IAM and RBAC permissions. Possessing a certificate and being authorized to perform an operation are separate matters.
Potential impact
- Unneeded legacy credentials can add access paths that may be misused if exposed.
- Excessive IAM or RBAC permissions can let authenticated users perform operations they do not need.
Remediation
- Avoid issuing unnecessary client certificates in new configurations and use supported authentication methods.
- Identify clients using existing certificates and migrate them to replacement authentication. Changing this option alone cannot remove certificates already issued.
- Remove unnecessary permission bindings and verify that required access works and unwanted access is denied.
Examples
Deployment Manager support has ended. These are authentication excerpts from a GKE Standard cluster request body. Supply the actual location, node and network configuration separately and use a supported management tool.
Before
name: my-cluster
masterAuth:
clientCertificateConfig:
issueClientCertificate: true
This requests issuance of a legacy client certificate.
After
name: my-cluster
masterAuth:
clientCertificateConfig:
issueClientCertificate: false
This does not request a client certificate. Actual client authentication and IAM/RBAC permissions still require separate configuration.