GEN000000-LNX00560 - The Linux NFS Server must not have the insecure file locking option.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Insecure file locking could allow for sensitive data to be viewed or edited by an unauthorized user.

Solution

Remove the 'insecure_locks' option from all NFS exports on the system.

Procedure:

Edit /etc/exports and remove all instances of the insecure_locks option.

Re-export the file systems to make the setting take effect.
# exportfs -a

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V1R14_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|I, CCI|CCI-000225, CCI|CCI-000764, Rule-ID|SV-62985r1_rule, STIG-ID|GEN000000-LNX00560, Vuln-ID|V-4339

Plugin: Unix

Control ID: d086e81abc9fd4a1cee3f6ef3602e85507eb914e0608198a8f0535ce57e03b7e