5.1.1.1.4 Ensure journald is not configured to receive logs from a remote client

Information

Journald supports the ability to receive messages from remote hosts, thus acting as a log server. Clients should not receive data from other hosts.

Note:

- The same package, systemd-journal-remote is used for both sending logs to remote hosts and receiving incoming logs.
- With regards to receiving logs, there are two services; systemd-journal-remote.socket and systemd-journal-remote.service

If a client is configured to also receive data, thus turning it into a server, the client system is acting outside it's operational boundary.

Solution

Run the following command to disable systemd-journal-remote.socket :

# systemctl --now disable systemd-journal-remote.socket

See Also

https://workbench.cisecurity.org/benchmarks/15023

Item Details

Category: AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

References: 800-53|AU-2, 800-53|AU-7, 800-53|AU-12, 800-53|CM-6, 800-53|CM-7, CSCv7|6.2, CSCv7|6.3, CSCv7|9.2

Plugin: Unix

Control ID: 15ff0d75d7441e94e7e2d5be45043bf7e9e97910b1c2ffe8f501608ed9d9a827