This is not the latest version of the STIG. This is provided for archival purposes. See the latest STIG.

RHEL 10 must disable network management of the chrony daemon.

STIG ID: RHEL-10-200543  |  SRG: SRG-OS-000096-GPOS-00050 |  Severity: medium (CAT II)  |  CCI: CCI-000382,CCI-000381 |  Vulnerability Id: V-280961

Vulnerability Discussion

Not exposing the management interface of the chrony daemon on the network diminishes the attack space.

Satisfies: SRG-OS-000096-GPOS-00050, SRG-OS-000095-GPOS-00049

Check

Verify RHEL 10 disables network management of the chrony daemon with the following command:

$ sudo grep -w cmdport /etc/chrony.conf
cmdport 0

If the "cmdport" option is not set to "0", is commented out, or is missing, this is a finding.

Fix

Configure RHEL 10 to disable network management of the chrony daemon by adding/modifying the following line in the "/etc/chrony.conf" file:

cmdport 0

Restart the chronyd service with the following command for the changes to take effect:

$ sudo systemctl restart chronyd