2.5 Disable Generic Security Services (GSS)

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The GSS API is a security abstraction layer that is designed to make it easier for developers
to integrate with different authentication schemes. It is most commonly used in
applications for sites that use Kerberos for network authentication, though it can also allow
applications to interoperate with other authentication schemes.

Rationale:

GSS does not expose anything external to the system as it is configured to use TLI (protocol
= ticotsord) by default. This service should be disabled if it is not required.

Solution

To disable this service, run the following command:

# svcadm disable svc:/network/rpc/gss

See Also

https://workbench.cisecurity.org/files/2582