2.2.10 Ensure a web server is not installed

Information

Web servers provide the ability to host web site content.

Unless there is a need to run the system as a web server, it is recommended that the packages be removed to reduce the potential attack surface.

Note: Several http servers exist. They should also be audited, and removed, if not required.

Solution

Run the following command to remove httpd and nginx :

# dnf remove httpd nginx

See Also

https://workbench.cisecurity.org/files/3796

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 90d72edcaa7c4c811a1ce27434fbec2a552733cd43b9073272cee04f1a23e83b