1.7.1.7 Ensure SETroubleshoot is not installed

Information

The SETroubleshoot service notifies desktop users of SELinux denials through a user-friendly interface. The service provides important information around configuration errors, unauthorized intrusions, and other potential errors.

Rationale:

The SETroubleshoot service is an unnecessary daemon to have running on a server, especially if X Windows is disabled.

Solution

Run the following command to Uninstall setroubleshoot:

# yum remove setroubleshoot

See Also

https://workbench.cisecurity.org/files/2925

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CSCv7|14.6

Plugin: Unix

Control ID: 8a828bc3890c9816a7e078e82b9b7a6e7856a98e23e3cf811c0ac5b264a8ea0c