SV-227013r603265_rule
V-227013
SRG-OS-000480
GEN005860
CAT II
10
Edit the /etc/dfs/dfstab file and add the sec=XXX option to the share line as an option. XXX must be a valid option for the system other than none.
Perform the following on NFS servers:
# grep "^default" /etc/nfssec.conf
Check to ensure the second column does not equal 0. This would indicate the default is set to none. Perform the following to check currently exported file systems.
# more /etc/dfs/dfstab
If the option sec=none is set on any of the exported file systems, this is a finding.
V-227013
False
GEN005860
Perform the following on NFS servers:
# grep "^default" /etc/nfssec.conf
Check to ensure the second column does not equal 0. This would indicate the default is set to none. Perform the following to check currently exported file systems.
# more /etc/dfs/dfstab
If the option sec=none is set on any of the exported file systems, this is a finding.
M
4060