2.3.5 Ensure LDAP client is not installed

Information

The Lightweight Directory Access Protocol (LDAP) was introduced as a replacement for NIS/YP. It is a service that provides a method for looking up information from a central database.
Rationale:
If the system will not need to act as an LDAP client, it is recommended that the software be removed to reduce the potential attack surface.

Solution

Uninstall ldap-utils using the appropriate package manager or manual installation:
# apt-get remove ldap-utils
Impact:
Removing the LDAP client will prevent or inhibit using LDAP for authentication in your environment.

See Also

https://workbench.cisecurity.org/files/2429

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|2, CSCv7|2.6

Plugin: Unix

Control ID: a444eb77595620802ad276e85d89f039f6e45d173298a0900f1402ed33160fbc