4.3.2.13 Ensure rwhod is not in use

Information

This entry starts the rwhod daemon on system startup. This is the remote WHO service.

The rwhod daemon is the remote WHO service, which collects and broadcasts status information to peer servers on the same network. It is recommended that this daemon is disabled, unless it is required.

Solution

- On AIX 7.1 and earlier comment out the rwhod entry in /etc/rc.tcpip and ensure service is stopped:

chrctcp -d rwhod
stopsrc -s rwhod
- On AIX 7.2 and later remove the software:

installp -ug bos.net.tcp.rcmd_server

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 69aae3fbb3c73135f203e6a969eec90f5ab2cb5eec9987be44c7fbdb9a1868ab