AlmaLinux OS 9 must not have the gssproxy package installed.

STIG ID: ALMA-09-029500  |  SRG: SRG-OS-000095-GPOS-00049 |  Severity: medium |  CCI: CCI-000381 |  Vulnerability Id: V-269340

Vulnerability Discussion

The gssproxy package is a proxy for GSS API credential handling and could expose secrets on some networks. It is not needed for normal function of the OS.

Check

Verify that the gssproxy package is not installed with the following command:

$ dnf list --installed gssproxy

Error: No matching Packages to list

If the "gssproxy" package is installed and is not documented with the information system security officer (ISSO) as an operational requirement, this is a finding.

Fix

Remove the gssproxy package with the following command:

$ dnf remove gssproxy