4.6.1.1 Ensure CDE is not installed

Information

The recommendation is to de-install CDE aka X11.Dt from the system, assuming that it is not required and is already installed.

CDE has a history of security problems and should be disabled.

NOTE: If CDE is required, it is vital to patch the software and consider TCP Wrappers to further enhance security.

Solution

Identity if CDE is already installed:

lslpp -L |grep -i X11.Dt

If there are CDE filesets installed - de-install them if CDE is not required. For each fileset preview the de-installation:

installp -up <fileset name>

Review the fileset removal preview output, paying particular attention to the other pre-requisites that will also be removed. Typically only X11.Dt filesets should be de-installed as pre-requisites. Once reviewed, de-install the fileset and pre-requisites:

installp -ug <fileset name>

NOTE: Repeat until all CDE related filesets are de-installed

See Also

https://workbench.cisecurity.org/benchmarks/22751

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 210413d054609380ec2849e766575a01de7953017637d12a3b93a6c3ad753ba3