3.1.5.14 login

Information

This entry starts the rlogin daemon when required. This service authenticates remote user logins.

Rationale:

This login service is used to authenticate a remote user connection when logging in via the rlogin command. The username and password are passed over the network in clear text and therefore insecurely. Unless required the rlogin daemon will be disabled. This function, if required, should be facilitated through SSH.

Solution

In /etc/inetd.conf, comment out the login entry and refresh the inetd process:

chsubserver -r inetd -C /etc/inetd.conf -d -v 'login' -p tcp6
lssrc -s inetd && refresh -s inetd

Default Value:

Uncommented

See Also

https://workbench.cisecurity.org/files/4119

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 78515e6c2b6fa5f004bdd70861d3d6923e564436e201578ff945f20ee48c9ea0