2.2.10 Ensure IMAP and POP3 server is not installed

Information

dovecot is an open source IMAP and POP3 server for Linux based systems.

Rationale:

Unless POP3 and/or IMAP servers are to be provided by this system, it is recommended that the package be removed to reduce the potential attack surface.

Notes:

Several IMAP/POP3 servers exist and can use other service names. courier-imap and cyrus-imap are example services that provide a mail server.

These and other services should also be audited and the packages removed if not required.

Solution

Run the following command to remove dovecot:

# yum remove dovecot

See Also

https://workbench.cisecurity.org/files/3148

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv7|9.2

Plugin: Unix

Control ID: 8b0e1c9c9aaddb9d47a821890e9f36e3f1dde88db28ea11cc16f938c804ecd04