The FTP daemon must not be installed unless required.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-216055SOL-11.1-020130SV-216055r959010_ruleCCI-000366high
Description
FTP is an insecure protocol.
STIGDate
Solaris 11 X86 Security Technical Implementation Guide2025-05-05

Details

Check Text (C-216055r959010_chk)

Determine if the FTP package is installed. # pkg list service/network/ftp If an installed package named "service/network/ftp" is listed and not required for operations, this is a finding.

Fix Text (F-17291r372548_fix)

The Software Installation Profile is required. # pfexec pkg uninstall service/network/ftp