3.1.5.29 tftp

Information

This entry starts the tftp service when required.

Rationale:

The tftp service allows remote systems to download or upload files to the tftp server without any authentication. It is therefore a service that should not run, unless needed. One of the main reasons for requiring this service to be activated is if the host is a NIM master. However, the service can be enabled and then disabled once a NIM operation has completed, rather than left running permanently.

Solution

Use chsubserver to disable this service in /etc/inetd.conf:

chsubserver -r inetd -C /etc/inetd.conf -d -v 'tftp' -p 'udp6'
refresh -s inetd

Default Value:

Disabled

See Also

https://workbench.cisecurity.org/files/4119

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: ea60d35048bf9dc36e72b0e6cc8611c355026a0da4914a82b7aed2376975ab0d