2.2.9 Ensure HTTP server is not installed

Information

HTTP or web servers provide the ability to host web site content.

Unless there is a need to run the system as a web server, it is recommended that the package be removed to reduce the potential attack surface.

Notes:

-

Several http servers exist. apache apache2 lighttpd and nginx are example packages that provide an HTTP server.

-

These and other packages should also be audited, and removed if not required.

Solution

Run the following command to remove httpd :

# yum remove httpd

See Also

https://workbench.cisecurity.org/benchmarks/8415

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 41561ec2cb4e79c59e0d2502041baf31ab02fedd36f3b8b4f2f6dc95eb69cb47