PHTN-67-000033 - The Photon operating system must disable the loading of unnecessary kernel modules - tipc

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

To support the requirements and principles of least functionality, the operating system must provide only essential capabilities and limit the use of modules, protocols, and/or services to only those required for the proper functioning of the product.

Satisfies: SRG-OS-000096-GPOS-00050, SRG-OS-000114-GPOS-00059

Solution

Open /etc/modprobe.d/modprobe.conf with a text editor and set the contents as follows:

install sctp /bin/false
install dccp /bin/false
install dccp_ipv4 /bin/false
install dccp_ipv6 /bin/false
install ipx /bin/false
install appletalk /bin/false
install decnet /bin/false
install rds /bin/false
install tipc /bin/false
install bluetooth /bin/false
install usb-storage /bin/false
install ieee1394 /bin/false
install cramfs /bin/false
install freevxfs /bin/false
install jffs2 /bin/false
install hfs /bin/false
install hfsplus /bin/false
install squashfs /bin/false
install udf /bin/false

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_6-7_Y22M04_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000382, CCI|CCI-000778, Rule-ID|SV-239105r816619_rule, STIG-ID|PHTN-67-000033, Vuln-ID|V-239105

Plugin: Unix

Control ID: 945ad76f13bc9fe436b7306d39a6a35a491f478cd6ba9bcd0ebbdd23a712253e