2.2.12 Ensure IMAP and POP3 server is not installed

Information

dovecot is an open source IMAP and POP3 server for Linux based systems.

Rationale:

Unless POP3 and/or IMAP servers are to be provided by this system, it is recommended that the package be removed to reduce the potential attack surface.

Notes:

Several IMAP/POP3 servers exist and can use other service names. courier-imap and cyrus-imap are example services that provide a mail server.

These and other services should also be audited and the packages removed if not required.

Solution

Run the following command to remove dovecot:

# yum remove dovecot

See Also

https://workbench.cisecurity.org/files/2925

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv7|9.2

Plugin: Unix

Control ID: b19ced07b293c4d8ee23822edb4275ffcb77e19484ea4081dac259ba18d69797