1.6.1.4 Ensure SETroubleshoot is not installed

Information

The SETroubleshoot service notifies desktop users of SELinux denials through a user-friendly interface. The service provides important information around configuration errors, unauthorized intrusions, and other potential errors. The SETroubleshoot service is an unnecessary daemon to have running on a server, especially if X Windows is disabled.

Solution

Run the following command to uninstall setroubleshoot: # zypper remove setroubleshoot

See Also

https://benchmarks.cisecurity.org/tools2/linux/CIS_SUSE_Linux_Enterprise_11_Benchmark_v2.0.0.pdf

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Unix

Control ID: 862490e035320ad4cad1ccb5f23225d9f2f8a4b41a986a16a2ff10e36e9063af