2.1.19 Ensure GNOME Display Manager is removed

Information

The GNOME Display Manager (GDM) is a program that manages graphical display servers and handles graphical user logins.

If a Graphical User Interface (GUI) is not required, it should be removed to reduce the attack surface of the system.

Solution

Run the following to remove the Server with GUI group:

- Run the following command to install the Minimal Install group:

# dnf groupinstall -y "Minimal Install"

Note: This is important to update dependencies to allow the removal of the Server with GUI group with minimal impact to the system functionality.

<xhtml:ol start="2"> - Run the following command to remove the Server with GUI group:

# dnf groupremove -y "Server with GUI" <xhtml:ol start="3"> - Run the following command to install the Server group:

# dnf groupinstall -y "Server" <xhtml:ol start="4"> - Run the following command to reboot the system:

# reboot

Impact:

Removing the GNOME Display manager will remove the Graphical User Interface (GUI) from the system.

See Also

https://workbench.cisecurity.org/benchmarks/24008

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 89399ed3fdfb41e2606e16a98a2f11f4e5cbaafa04b7575f422345e734a8e225