OL 8 must not have the "gssproxy" package installed if not required for operational support.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-248904
OL08-00-040370
SV-248904r991589_rule
Medium
Description
Verify the operating system is configured to disable non-essential capabilities. The most secure way of ensuring a non-essential capability is disabled is to not have the capability installed.
When an application uses Generic Security Services API (GSSAPI), typically it will have direct access to its security credentials, and all cryptographic operations are performed in the application's process. This is undesirable, but "gssproxy" can help in almost all use cases. It provides privilege separation to applications using the GSSAPI: The gssproxy daemon runs on the system, holds the application's credentials, and performs operations on behalf of the application.