OL6-00-000256 - The openldap-servers package must not be installed unless required.

Information

Unnecessary packages should not be installed to decrease the attack surface of the system.

Solution

The 'openldap-servers' package should be removed if not in use. Is this machine the OpenLDAP server? If not, remove the package.

# yum erase openldap-servers

The openldap-servers RPM may be installed. It is needed only by the OpenLDAP server, not by clients which use LDAP for authentication. If the system is not intended for use as an LDAP server, it should be removed.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_6_V2R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-208932r793718_rule, STIG-ID|OL6-00-000256, STIG-Legacy|SV-65027, STIG-Legacy|V-50821, Vuln-ID|V-208932

Plugin: Unix

Control ID: bdf36fbee2fbf50040e65115105d52bc267b669b643a1ff22c319a8e81bb2ae8