GEN005860 - The system's NFS export configuration must not have the sec option set to none (or equivalent); additionally, the default authentication must not to be set to none - nfssec.conf default

Information

If sec=none on Solaris, all NFS requests are mapped to an unknown/common user instead of being processed according to the provided UID.

Solution

Edit the /etc/dfs/dfstab file and add the sec=XXX option to the share line as an option. XXX must be a valid option for the system other than none.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_x86_V2R4_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-227920r603266_rule, STIG-ID|GEN005860, STIG-Legacy|SV-40306, STIG-Legacy|V-934, Vuln-ID|V-227920

Plugin: Unix

Control ID: 4014cc84adf760258b01357457cdf7d823135566f0362b344955294fd2769f83