2.1.7 Remove tftp

Information

Trivial File Transfer Protocol (TFTP) is a simple file transfer protocol, typically used to automatically transfer configuration or boot files between machines. TFTP does not support authentication and can be easily hacked. The package tftp is a client program that allows for connections to a tftp server.

Rationale:

It is recommended that TFTP be removed, unless there is a specific need for TFTP (such as a boot server). In that case, use extreme caution when configuring the services.

Solution

Run the following command to remove tftp:

# yum erase tftp

Default Value:

OS Default: Disabled

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-11, CSCv7|2.6

Plugin: Unix

Control ID: 70941e393702ea50ce466c9240729b8c0e82fc4cf8614ca589168225bfdecb82