3.11 Remove HTTP Server

Information

HTTP or web servers provide the ability to host web site content. The default HTTP server shipped with Red Hat Linux is Apache.

Rationale:

Unless there is a need to run the system as a web server, it is recommended that the package be deleted to reduce the potential attack surface.

Solution

Run the following command to remove httpd:

# yum erase httpd

Default Value:

OS Default: N/A

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-11, CSCv7|2.6

Plugin: Unix

Control ID: f5db9dd74a8a6c8c7707dd6dba91aa478dc8b44f869ab9d344fd3aeae03f68a6