UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The Network File System (NFS) server must not allow remote root access.


Overview

Finding ID Version Rule ID IA Controls Severity
V-935 GEN005880 SV-64157r1_rule EBRP-1 Medium
Description
If the NFS server allows root access to local file systems from remote hosts, this access could be used to compromise the system.
STIG Date
Oracle Linux 5 Security Technical Implementation Guide 2015-03-26

Details

Check Text ( C-52627r1_chk )
List the exports.
# cat /etc/exports
If any export contains "no_root_squash" or does not contain "root_squash" or "all_squash", this is a finding.
Fix Text (F-54761r1_fix)
Edit the "/etc/exports" file and add "root_squash" (or "all_squash") and remove "no_root_squash".