Rule ID
SV-45876r2_rule
Version
V1R12
CCIs
FTP is typically unencrypted and presents confidentiality and integrity risks. FTP may be protected by encryption in certain cases, such as when used in a Kerberos environment. SFTP and FTPS are encrypted alternatives to FTP.
Perform the following to determine if unencrypted FTP is enabled: # chkconfig --list pure-ftpd # chkconfig --list gssftp # chkconfig --list vsftpd If any of these services are found, ask the SA if these services are encrypted. If they are not, this is a finding.
Disable the FTP daemons. Procedure: # chkconfig pure-ftpd off # chkconfig gssftp off # chkconfig vsftpd off