Set the owner and owner group of the TLS CA certificate file to root:root, and set the permission to 400.
The TLS CA certificate file (the path of the CA certificate file is specified by --tlscacert) is protected from being tampered with. The certificate file is used by the specified CA certificate to authenticate the Docker server. Therefore, the owner and owner group of the CA certificate must be root, and the permission must be 400 to ensure the integrity of the CA certificate.
You can perform the following operations to set the file properties:
chown -h root:root <path to TLS CA certificate file>
Generally, the path to TLS CA certificate file is /usr/local/share/ca-certificates.
chmod 400 <path to TLS CA certificate file>
The owner and owner group of the Docker server certificate file are root:root, and the permission is set to 400.
chmod 400 <path to Docker server certificate file>
Protect the Docker server certificate file (the path of the certificate file is specified by the --tlscert parameter) from being tampered with. The certificate file is used to authenticate the Docker server based on the specified server certificate. Therefore, the owner and owner group of the CA certificate must be root, and the permission must be 400 to ensure the integrity of the certificate.
chown -h root:root <path to Docker server certificate file>
The owner and owner group of the Docker server certificate key file are root:root, and the permission is set to 400.
chmod 400 <path to Docker server certificate key file>
Protect the Docker server certificate key file (the path of the certificate file is specified by the --tlskey parameter) from being tampered with. The certificate key file contains the private key of the Docker server certificate. Therefore, the owner and owner group of the CA certificate must be root, and the permission must be 400 to ensure the integrity of the Docker server certificate.
chown -h root:root <path to Docker server certificate key file>
The owner and owner group of the daemon.json file are set to root:root, and the file permission is set to 600.
The daemon.json file contains sensitive parameters for changing the Docker daemon. It is an important global configuration file. The owner and owner group of the file must be root, and only the root user has the write permission on the file to ensure file integrity. This file does not exist by default.
docker --config-file=""
chown -h root:root /etc/docker/daemon.json
chmod 600 /etc/docker/daemon.json
If the file or directory does not exist, ignore this part.