Information
This entry starts the sendmail daemon on system startup. This means that the system can operate as a mail server.
Rationale:
sendmail is a service with many historical vulnerabilities and where possible should be disabled. If the system is not required to operate as a mail server i.e. sending, receiving or processing e-mail, comment out the sendmail entry.
Solution
On AIX 7.1 and earlier comment out the sendmail entry in /etc/rc.tcpip and ensure service is stopped:
chrctcp -d sendmail
stopsrc -s sendmail
On AIX 7.2 and later remove the software:
installp -u bos.net.tcp.sendmail
Default Value:
Enabled