2.2.11 Ensure IMAP and POP3 server is not enabled

Information

dovecot is an open source IMAP and POP3 server for Linux based systems.

Rationale:

Unless POP3 and/or IMAP servers are to be provided by this system, it is recommended
that the service be deleted to reduce the potential attack surface.

Solution

Run one of the following commands to disable dovecot :

# chkconfig dovecot off

# systemctl disable dovecot

# update-rc.d dovecot disable

Notes:

Additional methods of disabling a service exist. Consult your distribution documentation
for appropriate methods.

Several IMAP/POP3 servers exist and can use other service names. courier-imap and
cyrus-imap are example services that provide a mail server. These and other services
should also be audited.

See Also

https://workbench.cisecurity.org/files/2420

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1, CSCv7|9.2

Plugin: Unix

Control ID: 93a2c725266cac8f3a54840bef576338978af719c9435ed4c8dd9578b1d1eff1