2.2.1 Disable RPC Encryption Key - Make sure that /network/rpc/keyserv is disabled

Information

The keyserv process is only required for sites that are using Oracle's Secure RPC mechanism. The most common uses for Secure RPC on Solaris machines are NIS+ and 'secure NFS', which uses the Secure RPC mechanism to provide higher levels of security than the standard NFS protocols. Do not confuse 'secure NFS' with sites that use Kerberos authentication as a mechanism for providing higher levels of NFS security. 'Kerberized' NFS does not require the keyserv process to be running.

Solution

To disable the keyserv process, run the following command-
svcadm disable svc:/network/rpc/keyserv

See Also

https://workbench.cisecurity.org/files/614