Uninstall net-snmp Package

Esta página aún no está disponible en español. Estamos trabajando en su traducción.
Si tienes alguna pregunta o comentario sobre nuestro actual proyecto de traducción, no dudes en ponerte en contacto con nosotros.

Description

The snmp package provides the snmpd service. The snmp package can be removed with the following command:


$ apt-get remove snmp

Rationale

If there is no need to run SNMP server software, removing the package provides a safeguard against its activation.

Remediation

Shell script

The following script can be run on the host to remediate the issue.

#!/bin/bash

# CAUTION: This remediation script will remove snmp
# from the system, and may remove any packages
# that depend on snmp. Execute this
# remediation AFTER testing on a non-production
# system!


DEBIAN_FRONTEND=noninteractive apt-get remove -y "snmp"

Ansible playbook

The following playbook can be run with Ansible to remediate the issue.

- name: 'Uninstall net-snmp Package: Ensure snmp is removed'
  ansible.builtin.package:
    name: snmp
    state: absent
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_net-snmp_removed
  - unknown_severity