4.3.1.5 Ensure rcnfs service is not in use

Information

The rcnfs entry starts the NFS, NIS and automount daemons during system boot. Additionally, it automounts filesystems with the attribute vfs = nfs

NFS is a service with numerous historical vulnerabilities and should not be enabled unless there is no alternative

Solution

Use the rmitab command to remove the NFS start-up script from /etc/inittab :

rmitab rcnfs

Also, to be certain NFS related services have been discounted - execute the following script:

/etc/nfs.clean

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 79873b9db576e26b409c33678fbd21b39721b86947e551fbf080a0ec26054c83