1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47
|
documentation_complete: true
prodtype: alinux2,alinux3,fedora,ol7,ol8,rhcos4,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004,ubuntu2204
title: 'Ensure LDAP client is not installed'
description: |-
The Lightweight Directory Access Protocol (LDAP) is a service that provides
a method for looking up information from a central database.
{{{ describe_package_remove("openldap-clients") }}}
rationale:
If the system does not need to act as an LDAP client, it is recommended that the software is
removed to reduce the potential attack surface.
severity: low
identifiers:
cce@rhel7: CCE-82884-8
cce@rhel8: CCE-82885-5
cce@rhel9: CCE-90831-9
cce@sle12: CCE-91681-7
cce@sle15: CCE-91310-3
references:
cis@alinux2: 2.2.5
cis@alinux3: 2.3.3
cis@rhel7: 2.3.5
cis@rhel8: 2.3.5
cis@sle12: 2.3.5
cis@sle15: 2.3.5
cis@ubuntu2004: 2.3.5
cis@ubuntu2204: 2.3.5
pcidss: Req-2.2.4
ocil_clause: 'the package is installed'
ocil: |-
{{{ ocil_package("openldap-clients") }}}
template:
name: package_removed
vars:
pkgname: openldap-clients
pkgname@ubuntu1604: ldap-utils
pkgname@ubuntu1804: ldap-utils
pkgname@ubuntu2004: ldap-utils
|