ALMA-09-028620 - AlmaLinux OS 9 must prevent the chrony daemon from acting as a server.

Information

Being able to determine the system time of a server can be useful information for various attacks from timebomb attacks to location discovery based on time zone.

Minimizing the exposure of the server functionality of the chrony daemon reduces the attack surface.

Solution

Configure AlmaLinux OS 9 to disable the chrony daemon from acting as a server by adding/modifying the following line in the /etc/chrony.conf file:

port 0

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_CL_AlmaLinux_OS_9_V1R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCI|CCI-000381, Rule-ID|SV-269333r1050215_rule, STIG-ID|ALMA-09-028620, Vuln-ID|V-269333

Plugin: Unix

Control ID: d3e49662e2224f2d15a78a3a5278d92cd73d4b9a80473652eb40810d7eda2e21