AIX7-00-003047 - If sendmail is not required on AIX, the sendmail service must be disabled.

Information

The sendmail service has many historical vulnerabilities and, where possible, should be disabled. If the system is not required to operate as a mail server i.e. sending, receiving or processing e-mail, disable the sendmail daemon.

Solution

In '/etc/rc.tcpip', comment out the 'sendmail' entry by running command:
# chrctcp -d sendmail

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_IBM_AIX_7-x_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCI|CCI-000381, Rule-ID|SV-215353r958478_rule, STIG-ID|AIX7-00-003047, STIG-Legacy|SV-101429, STIG-Legacy|V-91331, Vuln-ID|V-215353

Plugin: Unix

Control ID: 1418e0df6187a2507462cdd69d899765a52fe9edd0b3f16fbbdf7e354ab584f1