1.300 RHEL-10-700115

Information

RHEL 10 must be configured so that the Network File System (NFS) is configured to use RPCSEC_GSS.

GROUP ID: V-281231RULE ID: SV-281231r1166645

When an NFS server is configured to use RPCSEC_SYS, a selected userid and groupid are used to handle requests from the remote user. The userid and groupid could mistakenly or maliciously be set incorrectly. The RPCSEC_GSS method of authentication uses certificates on the server and client systems to more securely authenticate the remote mount request.

Solution

Configure RHEL 10 so that the "/etc/fstab" file "sec" option is defined for each NFS mounted file system, and the "sec" option does not have the "sys" setting.

Ensure the "sec" option is defined as "krb5p:krb5i:krb5".

See Also

https://workbench.cisecurity.org/benchmarks/26403