This is not the latest version of the STIG. This is provided for archival purposes. See the latest STIG.

RHEL 10 must be configured to prevent unrestricted mail relaying.

STIG ID: RHEL-10-200692  |  SRG: SRG-OS-000095-GPOS-00049 |  Severity: medium (CAT II)  |  CCI: CCI-000381 |  Vulnerability Id: V-280999

Vulnerability Discussion

If unrestricted mail relaying is permitted, unauthorized senders could use this host as a mail relay to send spam or for other unauthorized activity.

Check

Note: If postfix is not installed, this is not applicable.

Verify RHEL 10 is configured to prevent unrestricted mail relaying with the following command:

$ postconf -n smtpd_client_restrictions
smtpd_client_restrictions = permit_mynetworks,reject

If the "smtpd_client_restrictions" parameter contains any entries other than "permit_mynetworks" and "reject", and the additional entries have not been documented with the information system security officer, this is a finding.

Fix

Configure RHEL 10 so that the postfix configuration file restricts client connections to the local network with the following command:

$ sudo postconf -e 'smtpd_client_restrictions = permit_mynetworks,reject'