4.1.5.29 tftp

Information

This entry starts the tftp service when required.

Rationale:

The tftp service allows remote systems to download or upload files to the tftp server without any authentication. It is therefore a service that should not run, unless needed. One of the main reasons for requiring this service to be activated is if the host is a NIM master. However, the service can be enabled and then disabled once a NIM operation has completed, rather than left running permanently.

Solution

Use chsubserver to disable this service in /etc/inetd.conf:

chsubserver -r inetd -C /etc/inetd.conf -d -v 'tftp' -p 'udp6'
refresh -s inetd

Default Value:

Disabled

See Also

https://workbench.cisecurity.org/benchmarks/13069

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: Unix

Control ID: 78f0600ffa828720c8ea54fe2910423ba2ecf0c027f4eb7dfbd1241bf68eb65a