SV-227012r603265_rule
V-227012
SRG-OS-000104
GEN005820
CAT II
10
Edit /etc/dfs/dfstab and add the "anon=-1" option for exports lacking it. Re-export the filesystems.
Check if the anon option is set correctly for exported file systems.
List exported file systems.
# exportfs -v
OR
# more /etc/dfs/sharetab
Each of the exported file systems should include an entry for the 'anon=' option set to -1 or an equivalent (60001, 60002, 65534, or 65535). If an appropriate 'anon=' setting is not present for an exported file system, this is a finding.
V-227012
False
GEN005820
Check if the anon option is set correctly for exported file systems.
List exported file systems.
# exportfs -v
OR
# more /etc/dfs/sharetab
Each of the exported file systems should include an entry for the 'anon=' option set to -1 or an equivalent (60001, 60002, 65534, or 65535). If an appropriate 'anon=' setting is not present for an exported file system, this is a finding.
M
4060