More Info:

Disable Client Certificates, which require certificate rotation, for authentication. Instead, use another authentication method like OpenID Connect.

Risk Level

Low

Address

Security, Reliability, Operational Excellence, Performance Efficiency

Compliance Standards

SOC2, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the misconfiguration “Ensure Authentication Using Client Certificates Is Disabled” in GCP using GCP console, you can follow the below steps:

  1. Open the GCP Console and navigate to the Security Command Center.

  2. From the Security Command Center dashboard, select the project that you want to remediate.

  3. Click on the “Policy” tab and search for the policy “Ensure Authentication Using Client Certificates Is Disabled”.

  4. Click on the policy to view the list of non-compliant resources.

  5. Click on the non-compliant resource that you want to remediate.

  6. In the “Resource Details” page, click on the “Remediate” button.

  7. In the “Remediation” dialog box, select the option “Disable client certificate authentication”.

  8. Click on the “Remediate” button to apply the remediation.

  9. Once the remediation is applied, the policy status will change to “Compliant”.

  10. Verify that the policy is now compliant by checking the policy status and the resource details page.

By following these steps, you can remediate the misconfiguration “Ensure Authentication Using Client Certificates Is Disabled” in GCP using GCP console.

Additional Reading: