RHEL-06-000515 - The NFS server must not have the all_squash option enabled.

Information

The 'all_squash' option maps all client requests to a single anonymous uid/gid on the NFS server, negating the ability to track file access by user ID.

Solution

Remove any instances of the 'all_squash' option from the file '/etc/exports'. Restart the NFS daemon for the changes to take effect.

# service nfs restart

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_6_V2R2_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2, CAT|III, CCI|CCI-000764, Rule-ID|SV-218095r603264_rule, STIG-ID|RHEL-06-000515, STIG-Legacy|SV-50260, STIG-Legacy|V-38460, Vuln-ID|V-218095

Plugin: Unix

Control ID: e3451bbe47d8db1b62b882dfb31832856df96b7428f6c18edcc0144b0929cb2b