2.2.24 Ensure NFS is configured to use RPCSEC_GSS

Information

The operating system must be configured so that the Network File System (NFS) is configured to use RPCSEC_GSS.

When an NFS server is configured to use RPCSEC_SYS, a selected userid and groupid are used to handle requests from the remote user. The userid and groupid could mistakenly or maliciously be set incorrectly. The RPCSEC_GSS method of authentication uses certificates on the server and client systems to more securely authenticate the remote mount request.

Solution

Update the /etc/fstab file so the option sec is defined for each NFS mounted file system and the sec option does not have the sys setting.

Example: vim /etc/fstab

Ensure the sec option is defined as krb5:krb5i:krb5p

192.168.21.5:/mnt/export /data1 nfs4 rw,sync ,soft,sec=krb5:krb5i:krb5p

See Also

https://workbench.cisecurity.org/benchmarks/8415

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 6d9ccf1a8793d937df826f40d12b48860bc89c777ef8cfe71294bc491cbc12fb