Disable Client Dynamic DNS Updates
An XCCDF Rule
Description
Dynamic DNS allows clients to dynamically update their own DNS records.
The updates are transmitted by unencrypted means which can reveal information
to a potential malicious user. If the system does not require Dynamic DNS,
remove all DHCP_HOSTNAME
references from the
/etc/sysconfig/network-scripts/ifcfg-interface
scripts. If
dhclient
is used, remove all send host-name hostname
references from the /etc/dhclient.conf
configuration file and/or any
reference from the /etc/dhcp
directory.
Rationale
Dynamic DNS updates transmit unencrypted information about a system including its name and address and should not be used unless needed.
- ID
- xccdf_org.ssgproject.content_rule_network_disable_ddns_interfaces
- Severity
- Medium
- References
- Updated