Contents

UEFI Secure Boot

Firewall Management

Certificate Management

Cert Manager

User Management

Auditing

Container Image Integrity (Signature Validation)

Container AppArmor Profile

Encrypting Data at Rest

Software Delivery Integrity

IPsec on Management Network

CVE Maintenance

Security Feature Configuration for Spectre and Meltdown

Deprecated Functionality

Appendix: Locally creating certificates