UCF STIG Viewer Logo

The NFS server must not allow remote root access.


Overview

Finding ID Version Rule ID IA Controls Severity
V-935 GEN005880 SV-935r2_rule EBRP-1 Medium
Description
If the NFS server allows root access to local file systems from remote hosts, this access could be used to compromise the system.
STIG Date
UNIX SRG 2013-03-26

Details

Check Text ( C-867r2_chk )
Determine if the NFS server is exporting with the root access option.

Procedure:
# exportfs -v | grep "root="

If an export with the root option is found, this is a finding.
Fix Text (F-1089r2_fix)
Edit /etc/exports and remove the root= option for all exports. Re-export the file systems.