GEN005750 - The NFS export configuration file must be group-owned by root, bin, sys, or system.

Information

Failure to give group ownership of the NFS export configuration file to root or a system group provides the designated group owner and possible unauthorized users with the potential to change system configuration which could weaken the system's security posture.

Solution

Change the group ownership of the NFS export configuration file to root, bin, sys, or system.
Procedure:
# chgrp root /etc/exports

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Rule-ID|SV-40861r1_rule, STIG-ID|GEN005750, Vuln-ID|V-22492

Plugin: Unix

Control ID: 64546c00492107e562295b53f7e1f6e4292589605fee6543a8013e069c9778ed