OL6-00-000515 - The NFS server must not have the all_squash option enabled.

Information

The 'all_squash' option maps all client requests to a single anonymous uid/gid on the NFS server, negating the ability to track file access by user ID.

Solution

Remove any instances of the 'all_squash' option from the file '/etc/exports'. Restart the NFS daemon for the changes to take effect.

# service nfs restart

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_6_V2R7_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2, CAT|III, CCI|CCI-000764, Rule-ID|SV-209060r793781_rule, STIG-ID|OL6-00-000515, STIG-Legacy|SV-64801, STIG-Legacy|V-50595, Vuln-ID|V-209060

Plugin: Unix

Control ID: 5e10ffb90b1e837c0e02c0f5b3023641469f1b4aa93647118cbddd48ed24b3fe