STIGQter STIGQter: STIG Summary: Oracle Linux 6 Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 23 Apr 2021:

The NFS server must not have the insecure file locking option enabled.

DISA Rule

SV-209031r603263_rule

Vulnerability Number

V-209031

Group Title

SRG-OS-000104

Rule Version

OL6-00-000309

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

By default the NFS server requires secure file-lock requests, which require credentials from the client in order to lock a file. Most NFS clients send credentials with file lock requests, however, there are a few clients that do not send credentials when requesting a file-lock, allowing the client to only be able to lock world-readable files.

To get around this, the "insecure_locks" option can be used so these clients can access the desired export.

This poses a security risk by potentially allowing the client access to data for which it does not have authorization.

Remove any instances of the "insecure_locks" option from the file "/etc/exports".

Check Contents

To verify insecure file locking has been disabled, run the following command:

# grep insecure_locks /etc/exports

If there is output, this is a finding.

Vulnerability Number

V-209031

Documentable

False

Rule Version

OL6-00-000309

Severity Override Guidance

To verify insecure file locking has been disabled, run the following command:

# grep insecure_locks /etc/exports

If there is output, this is a finding.

Check Content Reference

M

Target Key

2928

Comments