2.1.10 Ensure HTTP server is not enabled - status

Information

HTTP or web servers provide the ability to host web site content.

Rationale:

Unless there is a need to run the system as a web server, it is recommended that the service be disabled to reduce the potential attack surface.

Solution

Run the following command to disable httpd :

# systemctl disable httpd

# systemctl stop httpd

See Also

https://workbench.cisecurity.org/files/2449

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: Unix

Control ID: 438a8728ea3d473f792323f86c8f7abeaba002b453d3f0582946ff58be11db69