2.3.2 Ensure ldap client is not installed

Information

The Lightweight Directory Access Protocol (LDAP) was introduced as a replacement for NIS/YP. It is a service that provides a method for looking up information from a central database.

Rationale:

If the system will not need to act as an LDAP client, it is recommended that the software be removed to reduce the potential attack surface.

Impact:

Removing the LDAP client will prevent or inhibit using LDAP for authentication in your environment.

Solution

Run the following command to remove the openldap-clients package:

# dnf remove openldap-clients

See Also

https://workbench.cisecurity.org/benchmarks/15289

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|2.6

Plugin: Unix

Control ID: 8de621d4c71760911afd87b88ba153395eb123e39d1e0f21b9e84ddb73b57f28