2.1.5 Ensure time services are not enabled

Information

timeis a network service that responds with the server's current date and time as a 32 bit
integer. This service is intended for debugging and testing purposes. It is recommended
that this service be disabled.

Rationale:

Disabling this service will reduce the remote attack surface of the system.

Solution

Comment out or remove any lines starting with time from /etc/inetd.conf and
/etc/inetd.d/* .
Set disable = yes on all time services in /etc/xinetd.conf and /etc/xinetd.d/* .

See Also

https://workbench.cisecurity.org/files/2420

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1, CSCv7|9.2

Plugin: Unix

Control ID: 79a2c2282ad9dc4db7767e4294524c997097287a83ee6edfd0e845527dafd8bd