Hardening¶
NFS was designed in the 1980s for trusted campus networks. Its default configuration trusts client-supplied identity, transmits data in cleartext, and exposes the full filesystem through predictable file handles. Every default is wrong for a modern threat model.
Hardening NFS means layering defenses across four surfaces: authentication (who can claim which identity), authorization (what each export permits), network (who can reach the service), and protocol (which NFS versions and features are enabled). No single control is sufficient on its own.
Priority order¶
The checklist below is ordered by impact. Completing the Critical tier eliminates the majority of the attack surface documented in the findings catalog.
| Priority | Actions | Findings mitigated |
|---|---|---|
| Critical | Kerberos on all exports, no no_root_squash, separate filesystems per export, all_squash for public shares |
F-1.1, F-1.2, F-2.1, F-4.1 |
| High | Host/network restrictions, read-only where possible, fixed service ports, disable NFSv2/v3 | F-1.6, F-3.3, F-5.1, F-7.2 |
| Medium | subtree_check, portmapper restrictions, MOUNT DUMP monitoring, NFS over TLS |
F-2.6, F-3.1, F-5.4 |
Sub-pages¶
- Hardening checklist -- prioritized, actionable steps with finding cross-references
- Kerberos authentication -- deploying
sec=krb5pend-to-end - NFS over TLS -- RFC 9289 transport encryption
- Example configurations -- three complete
/etc/exportsfiles from maximum security to minimum acceptable
Verification¶
After applying hardening controls, verify them with nfswolf:
# Full security audit -- identifies every remaining weakness
nfswolf analyze target
# Verify escape is blocked (should fail on separate-filesystem exports)
nfswolf escape target:/export
# Confirm Kerberos enforcement (should report AUTH_TOOWEAK)
nfswolf scan target
Test from an attacker's perspective
The most reliable way to validate NFS hardening is to attack your own server. Run nfswolf analyze from an untrusted network segment -- every finding it reports is a gap in your defenses.