1.6.1.4 Ensure SETroubleshoot is not installed (Scored)
Profile Applicability
Level 2 - Server
Description
The SETroubleshoot service notifies desktop users of SELinux denials through a user-friendly interface. The service provides important information around configuration errors, unauthorized intrusions, and other potential errors.
Rationale
The SETroubleshoot service is an unnecessary daemon to have running on a server, especially if X Windows is disabled.
Audit
Run the following command and verify setroubleshoot
is not installed:
# rpm -q setroubleshoot package setroubleshoot is not installed
Remediation
Run the following command to uninstall setroubleshoot
:
# yum remove setroubleshoot