Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

DISA STIG Guidance

hoike is designed to be deployed on a host that is itself STIG-compliant — Red Hat Enterprise Linux under the Red Hat Enterprise Linux STIG, or OpenShift under the Container Platform SRG. Most controls are therefore inherited. This page maps the Application Security and Development STIG requirement families to what hoike provides, what is configuration, and what is still open, so that a checklist can be completed without re-deriving the answers. Exact rule IDs should be taken from the current benchmark release.

Inherited from the platform

Requirement familyProvided by
Operating system FIPS mode and crypto policyHost kernel and crypto-policies; hoike does not override them
Audit storage, protection, retention, and forwardingjournald or the platform collector; see Audit Logging
Time synchronizationchrony
Account management for the service userHost or platform identity
Network segmentation and firewallingHost firewall, OpenShift NetworkPolicy
Disk encryptionLUKS or the platform’s storage encryption
Malware and vulnerability scanning of the hostPlatform tooling

Met by hoike as shipped

Requirement familyHow
Input validation and bounded requestsOCSP body limit (max_request, 8,192 bytes default); admin login body 4,096 bytes with a 5-second read timeout; checked DER parsing; no unbounded upstream reads
Error messages do not reveal internalsStatic OCSP error responses; short admin error strings; no stack traces
No default or shared accountsOperators must be configured explicitly
Least privilegeContainer runs as a non-root user; no capabilities required
Separation of management and data interfacesadmin_listen and metrics_listen are distinct from the OCSP listener
Session termination on logoutDELETE /session invalidates the token
Role-based accessAdministrator, Operator, Viewer enforced on every admin route
Certificate expiry notificationKey-rotation monitor warns before responder_cert expiry
Third-party component trackingLocked dependency set with cargo audit in CI

Met by configuration

Requirement familySetting
Management traffic encryptedserver.admin_tls, server.metrics_tls; build with --features tls
Mutual authentication of administrative connectionsserver.admin_tls.client_ca
Use of an approved PKI for management TLSPoint client_ca and the server certificate at the organization’s or DoD’s issuing CA
Credentials not stored in clear textpin_env and bind_password_env instead of pin and bind_password; password hashes only in operators
Encrypted channels to backing servicesforward_to must be https://; directory tls = "ldaps" or "starttls"
Session lifetimesession_ttl_secs (set 900 or less for privileged nodes)
Non-production features disabledDo not use --demo-key, signing_key.type = "demo", or forward_insecure

Open in this release

Requirement familyStatusCompensating control until resolved
FIPS-validated cryptographic module for all security functionsOpen — see FIPS 140-3 StatusHSM-held signing keys; host FIPS mode for everything else on the box
Account lockout after consecutive failed loginsOpen (process-wide rate limit only)Mutual TLS on the admin listener; management-network-only access
Password complexity, minimum length, history, maximum ageOpen (hashes are operator-supplied)Enforce organizational policy when generating hashes; rotate on a schedule
DoD Notice and Consent BannerOpenPresent the banner on the management ingress or bastion in front of the admin listener
Session inactivity timeoutOpen (fixed lifetime only)Short session_ttl_secs
Concurrent session limit per userOpenProcedural
Re-authentication for privileged functionsOpenRestrict administrator role to a minimum set of accounts; mTLS
HTTP security headers on the web UIOpenServe the UI only over the mTLS admin listener; or omit server.webui
Audit of login success/failure and operator identity on privileged actionsOpenCorrelate admin-listener access logs at the ingress with hoike audit events
Signed release artifacts and imagesOpen (SHA-256 checksums only)Build from source in the organization’s pipeline and sign there
Application reports its versionOpenRecord the deployed image digest in the CMDB

All items in this table are scheduled; see the roadmap in the repository’s docs/compliance/ directory.

Evidence to collect for a checklist

  • hoike check --config /etc/hoike/hoike.toml output with no unexplained warnings
  • The effective configuration from GET /api/admin/config (secrets are redacted)
  • cargo audit report for the deployed lockfile
  • Container image digest and base image (Red Hat Universal Base Image once the rebase lands)
  • Host STIG scan results (OpenSCAP) for the node
  • Audit forwarding configuration and a sample rollback or fork event reaching the SIEM