UCF STIG Viewer Logo

The Network File System (NFS) server must not allow remote root access.


Overview

Finding ID Version Rule ID IA Controls Severity
V-935 GEN005880 SV-37859r1_rule EBRP-1 Medium
Description
If the NFS server allows root access to local file systems from remote hosts, this access could be used to compromise the system.
STIG Date
Red Hat Enterprise Linux 5 Security Technical Implementation Guide 2017-03-01

Details

Check Text ( C-37065r1_chk )
List the exports.
# cat /etc/exports
If any export contains "no_root_squash" or does not contain "root_squash" or "all_squash", this is a finding.

Fix Text (F-32333r1_fix)
Edit the "/etc/exports" file and add "root_squash" (or "all_squash") and remove "no_root_squash".