1.5.1.7 Ensure the MCS Translation Service (mcstrans) is not installed

Information

The mcstransd daemon provides category label information to client processes requesting information. The label translations are defined in /etc/selinux/targeted/setrans.conf

Rationale:

Since this service is not used very often, remove it to reduce the amount of potentially vulnerable code running on the system.

Solution

Run the following command to uninstall mcstrans:

# dnf remove mcstrans

See Also

https://workbench.cisecurity.org/benchmarks/15287

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 43c85631198e7f5d50bd6bcf01097e8670848fcd6f25a5d49bd8caf2ee5183d8