GEN007480 - The Reliable Datagram Sockets (RDS) protocol must be disabled or not installed unless required.

Information

The Reliable Datagram Sockets (RDS) protocol is a relatively new protocol developed by Oracle for communication between the nodes of a cluster. Binding this protocol to the network stack increases the attack surface of the host. Unprivileged local processes may be able to cause the system to dynamically load a protocol handler by opening a socket using the protocol.

Satisfies: SRG-OS-000096, SRG-OS-000510

Solution

Remove the RDS protocol handler package.
# pkgrm SUNWrds

OR

Prevent the RDS protocol handler from dynamic loading.
# echo 'exclude: rds' >> /etc/system

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_SPARC_V2R4_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CAT|II, CCI|CCI-000382, Rule-ID|SV-227050r603265_rule, STIG-ID|GEN007480, STIG-Legacy|SV-26894, STIG-Legacy|V-22530, Vuln-ID|V-227050

Plugin: Unix

Control ID: 60c41edf3dca420dc27dee7c3ea3a57dc906c725c9ba10432c3179f518bfea54