3.1.2.15 sendmail

Information

This entry starts the sendmail daemon on system startup. This means that the system can operate as a mail server.

Rationale:

sendmail is a service with many historical vulnerabilities and where possible should be disabled. If the system is not required to operate as a mail server i.e. sending, receiving or processing e-mail, comment out the sendmail entry.

Solution

In /etc/rc.tcpip, comment out the sendmail entry:

chrctcp -d sendmail

Default Value:

Uncommented

See Also

https://workbench.cisecurity.org/files/4119

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 3d3e90a3cc638dd5d1c01f0db6a2972ff631a55aa1ad65dffef2b8ebce2ab951