2.1.5 Ensure time services are not enabled (Scored)
Profile Applicability
Level 1 - Server Level 1 - Workstation
Description
time
is a network service that responds with the server's current date and time as a 32 bit integer. This service is intended for debugging and testing purposes. It is recommended that this service be disabled.
Rationale
Disabling this service will reduce the remote attack surface of the system.
Audit
Run the following command and verify time-dgram
and time-stream
are off or missing:
# chkconfig --list xinetd based services: time-dgram: off time-stream: off
Remediation
Run the following commands to disable time-dgram
and time-stream
:
# chkconfig time-dgram off # chkconfig time-stream off