2.3.5 Ensure LDAP client is not installed

Information

The Lightweight Directory Access Protocol (LDAP) was introduced as a replacement for
NIS/YP. It is a service that provides a method for looking up information from a central
database.

Rationale:

If the system will not need to act as an LDAP client, it is recommended that the software be
removed to reduce the potential attack surface.

Solution

Uninstall openldap-clients using the appropriate package manager or manual
installation:

# yum remove openldap-clients

# apt-get remove openldap-clients

# zypper remove openldap-clients

Impact:

Removing the LDAP client will prevent or inhibit using LDAP for authentication in your
environment.

Notes:

The openldap-clients package can go by other names on some distributions. openldap2-
client, and ldap-utils are known alternative package names.

See Also

https://workbench.cisecurity.org/files/2420

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-11, CSCv6|2, CSCv7|2.6

Plugin: Unix

Control ID: 1f7912228c24ec7bab47f2814b50469873a1c323b96fc2972aedad6f9e9d72fa