Check: WINSV-000103
Windows 2008 Domain Controller STIG:
WINSV-000103
(in versions v6 r47 through v6 r35)
Title
The Peer Networking Identity Manager service must be disabled if installed. (Cat II impact)
Discussion
Unnecessary services increase the attack surface of a system. Some of these services may not support required levels of authentication or encryption.
Check Content
Run "Services.msc". If the "Peer Networking Identity Manager" service (Service name: p2pimsvc) is installed and not disabled, this is a finding.
Fix Text
Remove or disable the "Peer Networking Identity Manager" service (Service name: p2pimsvc). The "Peer Networking Identity Manager" service may have been installed to support various functions, such as the "Peer Name Resolution Protocol". To remove the "Peer Name Resolution Protocol" from a system: Start "Server Manager" Select "Features" in the left pane. Under "Features Summary" in the right pane, select "Remove Features". On the "Features" screen, de-select "Peer Name Resolution Protocol ". Click "Next" and "Remove".
Additional Identifiers
Rule ID: SV-83311r1_rule
Vulnerability ID: V-26604
Group Title: Peer Networking Identity Manager Service Disabled
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000381 |
Configure the system to provide only organization-defined mission essential capabilities. |
Controls
Number | Title |
---|---|
CM-7 |
Least Functionality |