6.11 Ensure IMAP and POP server is not enabled

Information

Dovecot is an open source IMAP and POP3 server for Linux based systems.

*Rationale*

Unless POP3 and/or IMAP servers are to be provided to this server, it is recommended that
the service be deleted to reduce the potential attack surface.

Solution

Remove or comment out start lines in /etc/init/dovecot.conf-
#start on runlevel [2345]

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: Unix

Control ID: b3e64c596ffd151706f720983531a0bde63e1bcf206fdf94b71b4b70a4f2d622