2.2.10 Ensure a web server is not installed

Information

Web servers provide the ability to host web site content.

Unless there is a need to run the system as a web server, it is recommended that the packages be removed to reduce the potential attack surface.

Note: Several http servers exist. They should also be audited, and removed, if not required.

Solution

Run the following command to remove httpd and nginx :

# dnf remove httpd nginx

See Also

https://workbench.cisecurity.org/files/3742

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: d25ad0ff9ec7f9b5cb1288530cd14c10f05c365996d2c8da7bec29bf377b5521