2.2.10 Ensure IMAP and POP3 server is not installed

Information

dovecot is an open source IMAP and POP3 server for Linux based systems.

Rationale:

Unless POP3 and/or IMAP servers are to be provided by this system, it is recommended that the package be removed to reduce the potential attack surface.

Notes:

Several IMAP/POP3 servers exist and can use other service names. courier-imap and cyrus-imap are example services that provide a mail server.

These and other services should also be audited and the packages removed if not required.

Solution

Run the following command to remove dovecot:

# yum remove dovecot

See Also

https://workbench.cisecurity.org/files/3152

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv7|9.2

Plugin: Unix

Control ID: 79d80d3242d2eba5e159a7ec52424d432d994d09ae58a58fbc2b58572098a1c3