RHEL 9 must have the Postfix package installed.

STIG ID: RHEL-09-215101  |  SRG: SRG-OS-000304-GPOS-00121 |  Severity: medium |  CCI: CCI-000015 |  Vulnerability Id: V-272488

Vulnerability Discussion

Postfix is a free, open-source mail transfer agent (MTA) that sends and receives emails. It is a server-side application that can be used to set up a local mail server, create a null-client mail relay, use a Postfix server as a destination for multiple domains, or choose an LDAP directory instead of files for lookups. Postfix supports protocols such as LDAP, SMTP AUTH (SASL), and TLS. It uses the Simple Mail Transfer Protocol (SMTP) to transfer emails between servers.

Satisfies: SRG-OS-000304-GPOS-00121, SRG-OS-000343-GPOS-00134, SRG-OS-000363-GPOS-00150, SRG-OS-000447-GPOS-00201

Check

Verify that RHEL 9 has the Postfix package installed with the following command:

$ sudo dnf list --installed postfix

Example output:

postfix.x86_64 2:3.5.25-1.el9

If the "postfix" package is not installed, this is a finding.

Fix

Install the Postfix package with the following command:

$ sudo dnf install postfix