Description
Legacy GKE client certificates provide an access path in addition to the default OAuth authentication. Distributing and managing the certificate and private key adds operational work; disclosure can allow access within that identity’s permissions. This is separate from TLS certificate verification for the API server.
Potential impact
- Old authentication methods can make tracking and retirement harder.
- A disclosed client certificate and private key can let an unauthorized party authenticate.
Remediation
- Set
issue_client_certificate = falseto stop unnecessary legacy certificate issuance and use the default OAuth authentication. Minimize IAM and Kubernetes RBAC permissions as well. - Migrate procedures that use existing certificates and remove their associated permissions through supported procedures. Do not assume that changing the issuance setting revokes certificates already issued.
Examples
These excerpts compare client-certificate issuance. The setting does not disable server TLS verification; removing existing certificate permissions is a separate task.
Before
hcl
resource "google_container_cluster" "example" {
name = "marcellus-wallace"
location = "us-central1-a"
initial_node_count = 3
master_auth {
client_certificate_config {
issue_client_certificate = true
}
}
}
After
hcl
resource "google_container_cluster" "example" {
name = "marcellus-wallace"
location = "us-central1-a"
initial_node_count = 3
master_auth {
client_certificate_config {
issue_client_certificate = false
}
}
}
Explanation:
- Before: Legacy client-certificate issuance is requested.
- After: Legacy certificate issuance is disabled. Check existing certificates’ access separately.