Generic Security Services (GSS) must be disabled.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-216316SOL-11.1-030030SV-216316r959010_ruleCCI-000366low
Description
This service should be disabled if it is not required.
STIGDate
Solaris 11 SPARC Security Technical Implementation Guide2025-05-05

Details

Check Text (C-216316r959010_chk)

Determine the status of the Generic Security Services. # svcs -Ho state svc:/network/rpc/gss If the GSS service is reported as online, this is a finding.

Fix Text (F-17550r371037_fix)

The Service Management profile is required: Disable the GSS service. # pfexec svcadm disable svc:/network/rpc/gss