2.2.11 Ensure HTTP server is not installed

Information

HTTP or web servers provide the ability to host web site content.

Unless there is a need to run the system as a web server, it is recommended that the package be removed to reduce the potential attack surface.

Note:

- Several http servers exist. apache apache2 lighttpd and nginx are example packages that provide an HTTP server
- These and other packages should also be audited, and removed if not required

Solution

Run the following command to remove apache2 :

# zypper remove apache2

See Also

https://workbench.cisecurity.org/benchmarks/22179

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 92cd149efd2ba5e361c63927efeed2c29a0423a8879ae98a2f7fcd141ad01283