2.2.16 Ensure NIS Server is not enabled

Information

The NIS service is inherently an insecure system that has been vulnerable to DOS attacks, buffer overflows and has poor authentication for querying NIS maps. NIS generally been replaced by such protocols as Lightweight Directory Access Protocol (LDAP). It is recommended that the service be disabled and other, more secure services be used

Solution

Run the following command to disable ypserv - # chkconfig ypserv off

See Also

https://workbench.cisecurity.org/files/1863

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: Unix

Control ID: 99ad3626459caf4dd9185be0de714e89eb0f22eccb1387ec46c7dcf29b8ab77e