1.51 RHEL-09-215020

Information

RHEL 9 must not have the sendmail package installed.

GROUP ID: V-257827
RULE ID: SV-257827r1044892

The sendmail software was not developed with security in mind, and its design prevents it from being effectively contained by SELinux. Postfix must be used instead.

Satisfies: SRG-OS-000480-GPOS-00227, SRG-OS-000095-GPOS-00049

Solution

Remove the sendmail package with the following command:

$ sudo dnf remove sendmail

See Also

https://workbench.cisecurity.org/benchmarks/22008