3.1.2.12 portmap

Information

If all RPC services are disabled, disable the portmap daemon itself.

The portmap daemon is required for the RPC service. It converts the RPC program numbers into Internet port numbers. The daemon may be disabled if the server is not:

An NFS server

A NIS (YP) or NIS+ server

Running the CDE GUI

Running a third-party software application that relies on RPC support

Rationale:

If no RPC services are required then there is no need to start the portmap daemon at boot time.

A start of portmap can be done either manually, or scripted, should RPC port-mapping support be needed post-IPL.

Solution

Review any active RPC services:

rpcinfo -p localhost

NOTE: If there are active RPC services and the services are required, do not disable portmap.

Disable portmap if there are no active or required RPC services:

chrctcp -d portmap
stopsrc -s portmap

Default Value:

Enabled

Additional Information:

Reversion:

Restore in portmap startup in /etc/rc.tcpip:

chrctcp -a portmap

startsrc -s portmap

See Also

https://workbench.cisecurity.org/files/4119

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 930b1213fe469217d098a7a73a175d120deaae6cfa4cbc74af97e7dd3e12e2fc