2.2.19 Ensure rsh server is not enabled - rsh.socket

Information

The Berkeley rsh-server ( rsh , rlogin , rexec ) package contains legacy services that exchange credentials in clear-text.

Rationale:

These legacy services contain numerous security exposures and have been replaced with the more secure SSH package.

Solution

Run the following commands to disable rsh , rlogin , and rexec :

# systemctl disable rsh.socket
# systemctl disable rlogin.socket
# systemctl disable rexec.socket

See Also

https://workbench.cisecurity.org/files/2688

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv7|9.2

Plugin: Unix

Control ID: 558c64f26e574031d4593149df61bc63195eb07f84ea42296ff00eab025e40a3