1.3.1.8 Ensure SETroubleshoot is not installed

Information

The SETroubleshoot service notifies desktop users of SELinux denials through a user-friendly interface. The service provides important information around configuration errors, unauthorized intrusions, and other potential errors.

The SETroubleshoot service is an unnecessary daemon to have running on a server, especially if X Windows is disabled.

Solution

Run the following command to uninstall setroubleshoot :

# dnf remove setroubleshoot

See Also

https://workbench.cisecurity.org/benchmarks/18209

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|CM-6, 800-53|CM-7, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: 0c11abe6fc31f2c753af3b344ca7a35221ac2acb4b1092189d703f49165cad8d