Table of Contents

2.1.5 Ensure time services are not enabled (Scored)

Profile Applicability

Level 1 - Server 
Level 1 - Workstation

Description

time is a network service that responds with the server's current date and time as a 32 bit integer. This service is intended for debugging and testing purposes. It is recommended that this service be disabled.

Rationale

Disabling this service will reduce the remote attack surface of the system.

Audit

Run the following command and verify time-dgram and time-stream are off or missing:

# chkconfig --list 
xinetd based services: 
  time-dgram: off 
  time-stream: off

Remediation

Run the following commands to disable time-dgram and time-stream:

# chkconfig time-dgram off 
# chkconfig time-stream off