SV-248902r1106146_rule
V-248902
SRG-OS-000480-GPOS-00227
OL08-00-040350
CAT II
10
Configure the TFTP daemon to operate in secure mode with the following command:
$ sudo systemctl edit tftp.service
In the editor, enter:
[Service]
ExecStart=/usr/sbin/in.tftpd -s /var/lib/tftpboot
After making changes, reload the systemd daemon and restart the TFTP service as follows:
$ sudo systemctl daemon-reload
$ sudo systemctl restart tftp.service
Note: If TFTP is not required, it must not be installed. If TFTP is not installed, this rule is not applicable.
Check to see if TFTP server is installed with the following command:
$ sudo dnf list installed | grep tftp-server
tftp-server.x86_64 x.x-x.el8
Verify the TFTP daemon, if tftp.server is installed, is configured to operate in secure mode with the following command:
$ grep -i execstart /usr/lib/systemd/system/tftp.service
ExecStart=/usr/sbin/in.tftpd -s /var/lib/tftpboot
Note: The "-s" option ensures the TFTP server only serves files from the specified directory, which is a security measure to prevent unauthorized access to other parts of the file system.
V-248902
False
OL08-00-040350
Note: If TFTP is not required, it must not be installed. If TFTP is not installed, this rule is not applicable.
Check to see if TFTP server is installed with the following command:
$ sudo dnf list installed | grep tftp-server
tftp-server.x86_64 x.x-x.el8
Verify the TFTP daemon, if tftp.server is installed, is configured to operate in secure mode with the following command:
$ grep -i execstart /usr/lib/systemd/system/tftp.service
ExecStart=/usr/sbin/in.tftpd -s /var/lib/tftpboot
Note: The "-s" option ensures the TFTP server only serves files from the specified directory, which is a security measure to prevent unauthorized access to other parts of the file system.
M
5416