3.1.1.5 rcnfs

Information

The rcnfs entry starts the NFS daemons during system boot.

Rationale:

NFS is a service with numerous historical vulnerabilities and should not be enabled unless there is no alternative. If NFS serving is required, then read-only exports are recommended and no filesystem or directory should be exported with root access. Unless otherwise required the NFS daemons will be disabled.

Solution

Use the rmitab command to remove the NFS start-up script from /etc/inittab:

rmitab rcnfs

Default Value:

Uncommented

See Also

https://workbench.cisecurity.org/files/4119

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 95e0365f427013a87dad8ef454e8b1dd7455d6e5c02278aced6714aad46e731f