4.8.1 inetd - disabling inetd

Information

If all of services run and managed by inetd are disabled, disable the inetd daemon itself.

If all inetd services are disabled, then there is no need to start the daemon at boot time. An administrator can manually start the inetd service post-IPL, if any of the inetd controlled services are required.

Solution

Review any active inetd services-

refresh -s inetd
lssrc -ls inetd

NOTE- If there are active services and the services are required, do not disable inetd. Skip to the next section and consider the implementation of TCP Wrappers to secure access to these active services. If the active services are not required disable them via the chsubserver command.

Disable inetd if there are no active services-

chrctcp -d inetd
stopsrc -s inetd

See Also

https://workbench.cisecurity.org/files/528