2.1.13 Ensure HTTP Proxy Server is not enabled - status

Information

Squid is a standard proxy server used in many distributions and environments.

Rationale:

If there is no need for a proxy server, it is recommended that the squid proxy be disabled to reduce the potential attack surface.

Solution

Run the following command to disable squid :

# systemctl disable squid
# systemctl stop squid

See Also

https://workbench.cisecurity.org/files/2449

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: Unix

Control ID: 89014dbd3a1964ece68b1430bf4170821772d69069a128477a6f6b3cdcf2a3a2