Skip to content

Ensure /srv Located On Separate Partition

An XCCDF Rule

Description

If a file server (FTP, TFTP...) is hosted locally, create a separate partition for /srv at installation time (or migrate it later using LVM). If /srv will be mounted from another system such as an NFS server, then creating a separate partition is not necessary at installation time, and the mountpoint can instead be configured later.

Rationale

Srv deserves files for local network file server such as FTP. Ensuring that /srv is mounted on its own partition enables the setting of more restrictive mount options, and also helps ensure that users cannot trivially fill partitions used for log or audit data storage.

ID
xccdf_org.ssgproject.content_rule_partition_for_srv
Severity
Unknown
References
Updated



Remediation - Anaconda Pre-Install Instructions


part /srv

Remediation - OS Build Blueprint


[[customizations.filesystem]]
mountpoint = "/srv"
size = 1073741824