4.3.2.14 Ensure sendmail is not in use

Information

This entry starts the sendmail daemon on system startup. This means that the system can operate as a mail server.

sendmail is a service with many historical vulnerabilities and where possible should be disabled. If the system is not required to operate as a mail server i.e. sending, receiving or processing e-mail, comment out the sendmail entry.

Solution

- On AIX 7.1 and earlier comment out the sendmail entry in /etc/rc.tcpip and ensure service is stopped:

chrctcp -d sendmail
stopsrc -s sendmail
- On AIX 7.2 and later remove the software:

installp -u bos.net.tcp.sendmail

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: b2b012852047ed10350d84d3bb35f3ad68f5548042a33290bd7dd8256bf2dfcc