3.11 Remove HTTP Server

Information

HTTP or web servers provide the ability to host web site content. The default HTTP server shipped with Red Hat Linux is Apache.

Rationale:

Unless there is a need to run the system as a web server, it is recommended that the package be deleted to reduce the potential attack surface.

Solution

Run the following command to remove httpd:

# yum erase httpd

Default Value:

OS Default: N/A

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-11, CSCv7|2.6

Plugin: Unix

Control ID: c16b11e538c9f2bde714713e195e558e2e008be37f336dded902e83369d6f5c9