GEN005860 - The system's NFS export configuration must not have the sec option set to none (or equivalent); additionally, the default authentication must not to be set to none - sec=none

Information

If sec=none on Solaris, all NFS requests are mapped to an unknown/common user instead of being processed according to the provided UID.

Solution

Edit the /etc/dfs/dfstab file and add the sec=XXX option to the share line as an option. XXX must be a valid option for the system other than none.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_SPARC_V2R4_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-227013r603265_rule, STIG-ID|GEN005860, STIG-Legacy|SV-40306, STIG-Legacy|V-934, Vuln-ID|V-227013

Plugin: Unix

Control ID: 61a3646d16d37bb744abc9f67a632beacb351df84d21734da05aba765f66e5d8