AIX7-00-003046 - If NFS is not required on AIX, the NFS daemon must be disabled.

Information

The rcnfs entry starts the NFS daemons during system boot.

NFS is a service with numerous historical vulnerabilities and should not be enabled unless there is no alternative. If NFS serving is required, then read-only exports are recommended and no filesystem or directory should be exported with root access. Unless otherwise required the NFS daemons (rcnfs) will be disabled.

Solution

In '/etc/inittab', remove the 'rcnfs' entry by running the following command:
# rmitab rcnfs

To request the init command to re-examine the '/etc/inittab' file, enter:
# telinit q

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_IBM_AIX_7-x_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCI|CCI-000381, Rule-ID|SV-215352r958478_rule, STIG-ID|AIX7-00-003046, STIG-Legacy|SV-101427, STIG-Legacy|V-91329, Vuln-ID|V-215352

Plugin: Unix

Control ID: 3cff7a1f6a58f2e6334c0bd849dd871d5eed10f86e45076848a1a7732384f47f