2.2.11 Ensure IMAP and POP3 server is not installed

Information

dovecot is an open source IMAP and POP3 server for Linux based systems.

Unless POP3 and/or IMAP servers are to be provided by this system, it is recommended that the package be removed to reduce the potential attack surface.

Note: Several IMAP/POP3 servers exist and can use other service names. These should also be audited and the packages removed if not required.

Solution

Run the following command to remove dovecot and cyrus-imapd :

# dnf remove dovecot cyrus-imapd

See Also

https://workbench.cisecurity.org/files/3742

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 0003cf3f6e98addcdbcda9494061a520c7e62707999fb0e89898c97b1d1a5f1d