1.370 OL08-00-040370

Information

OL 8 must not have the "gssproxy" package installed if not required for operational support.

GROUP ID: V-248904RULE ID: SV-248904r1069143

Verify the operating system is configured to disable nonessential capabilities. The most secure way of ensuring a nonessential capability is disabled is to not have the capability installed.

When an application uses Generic Security Services API (GSSAPI), typically it will have direct access to its security credentials, and all cryptographic operations are performed in the application's process. This is undesirable, but "gssproxy" can help in almost all use cases. It provides privilege separation to applications using the GSSAPI: The gssproxy daemon runs on the system, holds the application's credentials, and performs operations on behalf of the application.

Solution

Configure OL 8 to disable nonessential capabilities by removing the "gssproxy" package from the system with the following command:

$ sudo yum remove gssproxy

See Also

https://workbench.cisecurity.org/benchmarks/23791