UBTU-16-030740 - An X Windows display manager must not be installed unless approved.

Information

Internet services that are not required for system or application processes must not be active to decrease the attack surface of the system. X Windows has a long history of security vulnerabilities and will not be used unless approved and documented.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Document the requirement for an X Windows server with the Information System Security Officer (ISSO) or remove the related packages with the following commands:

# sudo apt-get purge lightdm

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_CAN_Ubuntu_16-04_LTS_V2R3_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-215160r610931_rule, STIG-ID|UBTU-16-030740, STIG-Legacy|SV-90581, STIG-Legacy|V-75901, Vuln-ID|V-215160

Plugin: Unix

Control ID: d2affa6cf9394f59a55a432f9f9d4e9ecf9ab1442dd64f4425e5dd5d7876600d