SV-230532r627750_rule
V-230532
SRG-OS-000480-GPOS-00227
RHEL-08-040180
CAT II
10
Configure the system to mask the debug-shell systemd service with the following command:
$ sudo systemctl mask debug-shell.service
Created symlink /etc/systemd/system/debug-shell.service -> /dev/null
Reload the daemon to take effect.
$ sudo systemctl daemon-reload
Verify RHEL 8 is configured to mask the debug-shell systemd service with the following command:
$ sudo systemctl status debug-shell.service
debug-shell.service
Loaded: masked (Reason: Unit debug-shell.service is masked.)
Active: inactive (dead)
If the "debug-shell.service" is loaded and not masked, this is a finding.
V-230532
False
RHEL-08-040180
Verify RHEL 8 is configured to mask the debug-shell systemd service with the following command:
$ sudo systemctl status debug-shell.service
debug-shell.service
Loaded: masked (Reason: Unit debug-shell.service is masked.)
Active: inactive (dead)
If the "debug-shell.service" is loaded and not masked, this is a finding.
M
2921