hoike is designed to be deployed on a host that is itself STIG-compliant — Red Hat Enterprise Linux under the Red Hat Enterprise Linux STIG, or OpenShift under the Container Platform SRG. Most controls are therefore inherited. This page maps the Application Security and Development STIG requirement families to what hoike provides, what is configuration, and what is still open, so that a checklist can be completed without re-deriving the answers. Exact rule IDs should be taken from the current benchmark release.
OCSP body limit (max_request, 8,192 bytes default); admin login body 4,096 bytes with a 5-second read timeout; checked DER parsing; no unbounded upstream reads
Error messages do not reveal internals
Static OCSP error responses; short admin error strings; no stack traces
No default or shared accounts
Operators must be configured explicitly
Least privilege
Container runs as a non-root user; no capabilities required
Separation of management and data interfaces
admin_listen and metrics_listen are distinct from the OCSP listener
Session termination on logout
DELETE /session invalidates the token
Role-based access
Administrator, Operator, Viewer enforced on every admin route
Certificate expiry notification
Key-rotation monitor warns before responder_cert expiry