RHEL-07-040750 - The Red Hat Enterprise Linux operating system must be configured so that the Network File System (NFS) is configured to use RPCSEC_GSS.

Information

When an NFS server is configured to use RPCSEC_SYS, a selected userid and groupid are used to handle requests from the remote user. The userid and groupid could mistakenly or maliciously be set incorrectly. The RPCSEC_GSS method of authentication uses certificates on the server and client systems to more securely authenticate the remote mount request.

Solution

Update the '/etc/fstab' file so the option 'sec' is defined for each NFS mounted file system and the 'sec' option does not have the 'sys' setting.

Ensure the 'sec' option is defined as 'krb5:krb5i:krb5p'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_7_V3R15_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-204626r991589_rule, STIG-ID|RHEL-07-040750, STIG-Legacy|SV-86935, STIG-Legacy|V-72311, Vuln-ID|V-204626

Plugin: Unix

Control ID: 6be45fdc7e62bb0481f722424ee54a5177cbdd0c4061bf2d570b8fe5383e0147