Uninstall nfs-utils Package

Classification:

compliance

Framework:

Control:

Description

The nfs-utils package can be removed with the following command:


$ sudo yum erase nfs-utils

Rationale

nfs-utils provides a daemon for the kernel NFS server and related tools. This package also contains the showmount program. showmount queries the mount daemon on a remote host for information about the Network File System (NFS) server on the remote host. For example, showmount can display the clients which are mounted on that host.

Remediation

Shell script

The following script can be run on the host to remediate the issue.

# CAUTION: This remediation script will remove nfs-utils
# from the system, and may remove any packages
# that depend on nfs-utils. Execute this
# remediation AFTER testing on a non-production
# system!

if rpm -q --quiet "nfs-utils" ; then

 yum remove -y "nfs-utils"

fi

Ansible playbook

The following playbook can be run with Ansible to remediate the issue.

- name: Ensure nfs-utils is removed
 package:
 name: nfs-utils
 state: absent
 tags:
 - CCE-82933-3
 - PCI-DSSv4-2.2.4
 - disable\_strategy
 - low\_complexity
 - low\_disruption
 - low\_severity
 - no\_reboot\_needed
 - package\_nfs-utils\_removed