STIGQter STIGQter: STIG Summary: Red Hat Enterprise Linux 8 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 23 Apr 2021:

RHEL 8 must be configured to prevent unrestricted mail relaying.

DISA Rule

SV-230550r627750_rule

Vulnerability Number

V-230550

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

RHEL-08-040290

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If "postfix" is installed, modify the "/etc/postfix/main.cf" file to restrict client connections to the local network with the following command:

$ sudo postconf -e 'smtpd_client_restrictions = permit_mynetworks,reject'

Check Contents

Verify the system is configured to prevent unrestricted mail relaying.

Determine if "postfix" is installed with the following commands:

$ sudo yum list installed postfix

postfix.x86_64 2:3.3.1-9.el8

If postfix is not installed, this is Not Applicable.

If postfix is installed, determine if it is configured to reject connections from unknown or untrusted networks with the following command:

$ sudo postconf -n smtpd_client_restrictions

smtpd_client_restrictions = permit_mynetworks, reject

If the "smtpd_client_restrictions" parameter contains any entries other than "permit_mynetworks" and "reject", this is a finding.

Vulnerability Number

V-230550

Documentable

False

Rule Version

RHEL-08-040290

Severity Override Guidance

Verify the system is configured to prevent unrestricted mail relaying.

Determine if "postfix" is installed with the following commands:

$ sudo yum list installed postfix

postfix.x86_64 2:3.3.1-9.el8

If postfix is not installed, this is Not Applicable.

If postfix is installed, determine if it is configured to reject connections from unknown or untrusted networks with the following command:

$ sudo postconf -n smtpd_client_restrictions

smtpd_client_restrictions = permit_mynetworks, reject

If the "smtpd_client_restrictions" parameter contains any entries other than "permit_mynetworks" and "reject", this is a finding.

Check Content Reference

M

Target Key

2921

Comments