Description
When clients use certificates to access kube-apiserver or kubelet, configure the trusted CA correctly. --client-ca-file or authentication.x509.clientCAFile points to CA certificates used to validate client identity. A filename extension does not determine certificate contents or trust scope.
Other supported authentication methods are possible, so the presence or absence of this CA setting alone does not establish anonymous access. Review authorization separately from authentication.
Potential impact
- An incorrect CA or unavailable file can prevent legitimate clients from authenticating.
- Excessive trust can accept unintended certificates as identities, increasing access risk depending on authorization.
Remediation
- If certificate authentication is required, specify a PEM bundle of trusted CA certificates and verify its path, mount and read permissions.
- Restrict CA issuance and replacement permissions; review certificate validity and required user and group permissions.
- Test that approved certificates succeed, untrusted certificates are rejected and intended authorization policies apply.
Examples
These excerpts compare only the kubelet CA path. foo/bar is an image placeholder; supply the actual kubelet, configuration and file mounts separately.
Before
apiVersion: v1
kind: Pod
metadata:
name: kubelet
spec:
containers:
- name: kubelet
image: foo/bar
command:
- "kubelet"
args:
- "--client-ca-file=/var/lib/ca.txt"
A file named ca.txt can also contain valid PEM CA certificates. Check its contents and whether the issuer is trusted.
After
apiVersion: v1
kind: Pod
metadata:
name: kubelet
spec:
containers:
- name: kubelet
image: foo/bar
command:
- "kubelet"
args:
- "--client-ca-file=/var/lib/ca.pem"
This specifies the ca.pem path. Renaming a file does not establish correct authentication; validate the actual CA certificates and client authentication.