4.3.1.5 Ensure rcnfs service is not in use

Information

The rcnfs entry starts the NFS, NIS and automount daemons during system boot. Additionally, it automounts filesystems with the attribute vfs = nfs

NFS is a service with numerous historical vulnerabilities and should not be enabled unless there is no alternative

Solution

Use the chitab command to disable the NFS start-up script in /etc/inittab :

Note: Do not use the rmitab to remove the NFS start-up script from /etc/inittab as it may return during a update.

chitab "rcnfs:23456789:off:/etc/rc.nfs > /dev/console 2>&1 # Start NFS Daemons"

Also, to be certain NFS and NIS related services have been stopped - execute the following script:

/etc/nfs.clean

See Also

https://workbench.cisecurity.org/benchmarks/19066

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 79873b9db576e26b409c33678fbd21b39721b86947e551fbf080a0ec26054c83