Deploy Cyberwatch in compliance with CCN-STIC 807

The CCN-STIC 807 guide (Criptología de empleo en el Esquema Nacional de Seguridad), published by the Centro Criptológico Nacional (CCN) of Spain, defines the cryptographic requirements applicable to organizations subject to the Esquema Nacional de Seguridad (ENS). In particular, it mandates the use of state-of-the-art cryptographic protocols (TLS 1.3) and control over deployed components.

This page describes the adaptations to be made to the deployment of Cyberwatch to meet these requirements. It complements the standard deployment with Swarm and the page Deploy Cyberwatch on a hardened environment.

The recommendations on this page apply only to organizations actually subject to CCN-STIC 807. They are not necessary for a standard deployment and may unnecessarily complicate installation in other contexts.

1. Disabling the embedded Elasticsearch and Kibana

By default, Cyberwatch embeds its own Elasticsearch and Kibana instances. In an environment subject to CCN-STIC 807, these embedded containers must be disabled, as their cryptographic configuration is not controlled by the organization.

Follow the procedure disabling embedded containers (flag CBW_DISABLE_ELK), documented for Docker Swarm, Podman, and the Helm chart.

If features relying on Elasticsearch and Kibana are still required, it is possible to connect Cyberwatch to an internally deployed Elastic Stack configured in accordance with your security policy. The configuration procedure for an external Elastic Stack describes the required settings (URL, authentication, CA certificate, TLS verification method).

2. Downloading the Cyberwatch package over TLS 1.3

The standard deployment adds the Cyberwatch repository and then installs the package via the distribution’s package manager (apt, dnf).

Depending on the operating system, the package manager’s TLS client does not always meet the necessary prerequisites (TLS 1.3 negotiation) to be compliant with CCN-STIC 807. In this case, do not configure the Cyberwatch repository: download the package manually with curl forcing TLS 1.3, then install it locally.

Retrieve the cyberwatch and cosign packages suitable for your distribution by forcing TLS 1.3 with the options --tlsv1.3 --tls-max 1.3:

Installing the Cyberwatch package may require adding dependencies not yet present on the system, such as docker, logrotate, openssl, bash-completion, or curl for example. These should be installed from the relevant distribution repositories.

On Debian-based distributions (apt repository):

# The exact (versioned) name of the cosign package is visible on https://dl.cyberwatch.com/apt/incoming/
curl --tlsv1.3 --tls-max 1.3 -JLO https://dl.cyberwatch.com/apt/incoming/cyberwatch.deb
curl --tlsv1.3 --tls-max 1.3 -JLO https://dl.cyberwatch.com/apt/incoming/cosign_<version>.deb
sudo dpkg -i cosign*.deb
sudo dpkg -i cyberwatch.deb

On Red Hat-based distributions (rpm repository):

# The exact (versioned) name of the cosign package is visible on https://dl.cyberwatch.com/rpm/incoming/
curl --tlsv1.3 --tls-max 1.3 -JLO https://dl.cyberwatch.com/rpm/incoming/cyberwatch.rpm
curl --tlsv1.3 --tls-max 1.3 -JLO https://dl.cyberwatch.com/rpm/incoming/cosign-<version>.rpm
sudo rpm -i cosign*.rpm
sudo rpm -i cyberwatch.rpm

3. Importing the container images with docker load

The installation then downloads the container images from the Cyberwatch registry (harbor.cyberwatch.fr) using the Docker daemon.

The official Docker daemon’s TLS client is currently not compliant with CCN-STIC 807. Therefore, it must not be used to retrieve the images. Instead, download the image archive from dl.cyberwatch.com (over TLS 1.3) and then import them locally with docker load.

Follow the procedure Download and import container images by forcing TLS 1.3 on the curl download:

export CBW_USER=
export CBW_PASSWORD=
curl --tlsv1.3 --tls-max 1.3 -u "$CBW_USER:$CBW_PASSWORD" -JLO https://dl.cyberwatch.com/download_images
docker image load -i images_cbwonpremise_*.tar.gz

Disable image downloads by setting the variable CBW_NO_PULL="true" in the /etc/cyberwatch/config.env file.

Since the images are present in the local cache, the Docker daemon does not need to retrieve them from the registry during configuration.

4. Blocking the Docker daemon’s outbound connections

Even with the images loaded locally and CBW_NO_PULL="true", the Docker daemon may still attempt to connect to the registry: when deploying the stack, Docker Swarm in particular tries to resolve the image digest. Since the daemon’s TLS client is not compliant with CCN-STIC 807, these residual connections must be blocked.

To do this, configure an intentionally unreachable proxy on the docker service, which will immediately fail any outbound connection from the daemon:

sudo mkdir -p /etc/systemd/system/docker.service.d

sudo tee /etc/systemd/system/docker.service.d/http-proxy.conf <<EOL
[Service]
Environment="HTTP_PROXY=http://127.0.0.2:9"
Environment="HTTPS_PROXY=http://127.0.0.2:9"
EOL

Apply the changes:

sudo systemctl daemon-reload
sudo systemctl restart docker

Apply this configuration on each Cyberwatch node (master/satellite).

5. Configuring Cyberwatch

Once the package is installed, the images imported, ELK deactivation set, and the Docker proxy configured, configure the application:

sudo cyberwatch configure

Then continue with the installation wizard as described in the standard deployment with Swarm.

This page covers the recommended deployment with Docker Swarm. The same principles apply to Podman deployments: ELK deactivation is documented, and manual image import over TLS 1.3 follows the same logic (podman image load, preloading into the cluster’s registry). Similarly for Kubernetes, it is necessary to configure global.image.pullPolicy: Never in the values.yml and to load the images according to the image storage engine associated with the Kubernetes cluster. This is only necessary if downloading the images does not meet the requirements regarding TLS 1.3.

Technical support

For any questions regarding a deployment subject to CCN-STIC 807, contact Cyberwatch support: