Re: [chrony-users] (SCAP-Finding) command port has to be closed

[ Thread Index | Date Index | More chrony.tuxfamily.org/chrony-users Archives ]


On Wed, Aug 21, 2024 at 01:53:13PM +0200, Nuß Bratling wrote:
> Hi,
> 
> There are these rules:
> RHEL9:
> https://www.stigviewer.com/stig/red_hat_enterprise_linux_9/2023-09-13/finding/V-257947
> RHEL8:
> https://www.stigviewer.com/stig/red_hat_enterprise_linux_8/2021-06-14/finding/V-230486

> I don't know if you know about these rules, and if no, would bringt it to
> your attention, that this rules perhaps should be changes, or, if you do
> know about these rules, I would like to ask what the rationale behind those
> are.

I'm aware that this thing exists and I agree that some of the
suggestions are questionable. It might depend on the use case. If
nothing is expected to be talking to the UDP port, it makes sense to
close it.

-- 
Miroslav Lichvar


-- 
To unsubscribe email chrony-users-request@xxxxxxxxxxxxxxxxxxxx 
with "unsubscribe" in the subject.
For help email chrony-users-request@xxxxxxxxxxxxxxxxxxxx 
with "help" in the subject.
Trouble?  Email listmaster@xxxxxxxxxxxxxxxxxxxx.


Mail converted by MHonArc 2.6.19+ http://listengine.tuxfamily.org/