5.1.2.1.4 Ensure journald is not configured to receive logs from a remote client

Information

Journald supports the ability to receive messages from remote hosts, thus acting as a log server. Clients should not receive data from other hosts.

NOTE:

- The same package, systemd-journal-remote is used for both sending logs to remote hosts and receiving incoming logs.
- With regards to receiving logs, there are two services; systemd-journal-remote.socket and systemd-journal-remote.service

If a client is configured to also receive data, thus turning it into a server, the client system is acting outside it's operational boundary.

Solution

Run the following command to disable systemd-journal-remote.socket :

# systemctl --now mask systemd-journal-remote.socket

See Also

https://workbench.cisecurity.org/benchmarks/15286

Item Details

Category: AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

References: 800-53|AU-2, 800-53|AU-7, 800-53|AU-12, 800-53|CM-6, 800-53|CM-7, CSCv7|6.2, CSCv7|6.3, CSCv7|9.2

Plugin: Unix

Control ID: b1052f25500f6bb2bd79f86f297d7f94ff3ec4d5569e9489dfcdfb0c5ada8ca3