2.1.13 Ensure HTTP Proxy Server is not enabled - status

Information

Squid is a standard proxy server used in many distributions and environments.

Rationale:

If there is no need for a proxy server, it is recommended that the squid proxy be disabled to reduce the potential attack surface.

Solution

Run the following command to disable squid :

# systemctl disable squid
# systemctl stop squid

See Also

https://workbench.cisecurity.org/files/2449

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv7|9.2

Plugin: Unix

Control ID: 794d31068ef36fef7a008459b76f0427c2c6aaa6b3e04404c067a6da24c9cd2d