UCF STIG Viewer Logo

The NFS server must not allow remote root access.


Overview

Finding ID Version Rule ID IA Controls Severity
V-227014 GEN005880 SV-227014r603265_rule Medium
Description
If the NFS server allows root access to local file systems from remote hosts, this access could be used to compromise the system.
STIG Date
Solaris 10 SPARC Security Technical Implementation Guide 2020-12-04

Details

Check Text ( C-29176r485390_chk )
Determine if the NFS server is exporting with the root access option.

Procedure:
# exportfs -v | grep "root="
OR
# more /etc/dfs/sharetab

If an export with the root option is found and is not properly documented with the IA staff, this is a finding.
Fix Text (F-29164r485391_fix)
Edit the /etc/dfs/dfstab file and remove the root= option from all exports. Re-export the file systems.