2.1.5 Ensure time services are not enabled - 'time-stream'

Information

time is a network service that responds with the server's current date and time as a 32 bit integer. This service is intended for debugging and testing purposes. It is recommended that this service be disabled. Disabling this service will reduce the remote attack surface of the system.

Solution

Comment out or remove any lines starting with time from /etc/inetd.conf and /etc/inetd.d/*. Set disable = yes on all time services in /etc/xinetd.conf and /etc/xinetd.d/*.

See Also

https://workbench.cisecurity.org/files/1866

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: Unix

Control ID: 868b6cf74953e3f41314061f0ec35d4f3598f254dd64c8a1321d26c78565e7f4