2.3.5 Ensure LDAP client is not installed - dpkg

Information

If the system will not need to act as an LDAP client, it is recommended that the software be removed to reduce the potential attack surface.

Solution

Uninstall openldap-clients using the appropriate package manager or manual installation:
# yum remove openldap-clients
# apt-get remove openldap-clients
# zypper remove openldap-clients

See Also

https://workbench.cisecurity.org/files/1856

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Unix

Control ID: 797b752e0f6f1422d8f06aa31938d46aaab7d16821a36af2b6da1f4379ede6a4