1.2.4 Disable the rhnsd Daemon

Information

The rhnsd daemon polls the Red Hat Network web site for scheduled actions.

Rationale:

Patch management policies may require that organizations test the impact of a patch before it is deployed in a production environment. Having patches automatically deployed could have a negative impact on the environment. It is best to not allow an action by default but only after appropriate consideration has been made. It is recommended that the service be disabled unless the risk is understood and accepted. This is not scorable item since organizations may have addressed the risk.

Solution

Disable the rhnsd daemon by running the following command:

# chkconfig rhnsd off

Default Value:

OS Default: N/A

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv6|9.1, CSCv7|9.2

Plugin: Unix

Control ID: 817c8d5ac056f1db8dd6570c9222883599380a1a8836acbb51350765c7c08fe7