2.2.8 Ensure a web server is not installed

Information

Web servers provide the ability to host web site content.

Unless there is a need to run the system as a web server, it is recommended that the packages be removed to reduce the potential attack surface.

Note: Several http servers exist. They should also be audited, and removed, if not required.

Solution

Run the following command to remove httpd and nginx :

# dnf remove httpd nginx

See Also

https://workbench.cisecurity.org/benchmarks/12705

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: b457adcedab5040f7b70edf36f2d8026e92c4d671018640aa7d973efe040dede