1.7.1.6 Ensure SETroubleshoot is not installed

Information

The SETroubleshoot service notifies desktop users of SELinux denials through a user-friendly interface. The service provides important information around configuration errors, unauthorized intrusions, and other potential errors. The SETroubleshoot service is an unnecessary daemon to have running on a server, especially if X Windows is disabled.

Solution

Run the following command to uninstall setroubleshoot:

# dnf remove setroubleshoot

See Also

https://workbench.cisecurity.org/files/2521

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(4), CSCv7|14.6

Plugin: Unix

Control ID: b8ab1d6bbd5e813dc3286dc132875fb39bc41b8c3665c979cc6533db49327c56