1. Home
  2. Security Hardening
  3. CIS Docker 1.6 V1.0.0 L1.Linux
  4. Audit Docker files and directories – docker-registry.service

Audit Docker files and directories – docker-registry.service

Details

Audit /usr/lib/systemd/system/docker-registry.service, if applicable.

Apart from auditing your regular Linux file system and system calls, audit all Docker

related files and directories. Docker daemon runs with ‘root’ privileges. Its behavior

depends on some key files and directories. /usr/lib/systemd/system/docker-

registry.service is one such file. It holds various parameters for Docker registries. It

must be audited, if applicable.

Solution

Add a rule for /usr/lib/systemd/system/docker-registry.service file.

For example,Add the line as below in /etc/audit/audit.rules file

–w /usr/lib/systemd/system/docker-registry.service -k docker

Then, restart the audit daemon.

For example,
#> service auditd restart

Impact-Auditing generates quite big log files. Ensure to rotate and archive them periodically. Also,
create a separate partition of audit to avoid filling root file system.

Default Value-By default, Docker related files and directories are not audited. The
file /usr/lib/systemd/system/docker-registry.service may not be available on the
system

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Audit and Accountability.This control applies to the following type of system Unix.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles