Restrict Information Published by Avahi
An XCCDF Rule
Description
If it is necessary to publish some information to the network, it should not be joined
by any extraneous information, or by information supplied by a non-trusted source
on the system.
Prevent user applications from using Avahi to publish services by adding or
correcting the following line in the [publish]
section:
disable-user-service-publishing=yesImplement as many of the following lines as possible, to restrict the information published by Avahi.
publish-addresses=no publish-hinfo=no publish-workstation=no publish-domain=noInspect the files in the directory
/etc/avahi/services/
. Unless there
is an operational need to publish information about each of these services,
delete the corresponding file.
Rationale
These options prevent publishing attempts from succeeding, and can be applied even if publishing is disabled entirely via disable-publishing. Alternatively, these can be used to restrict the types of published information in the event that some information must be published.
- ID
- xccdf_org.ssgproject.content_rule_avahi_restrict_published_information
- Severity
- Low
- References
- Updated