Skip to content

hidepid=2 should be enabled #1648

Closed
Closed
@trevor-vaughan

Description

@trevor-vaughan

A warning caveat should be placed in EL7 systems that note that setting the gid= option on the /proc mount will necessitate starting mcstransd with the same Group option if it is in use.

Enabling hidepid=2 enhances least privilege protections on the system by ensuring that users can only see the processes for which they are responsible.

See proc(5) for additional details.

Metadata

Metadata

Assignees

No one assigned

    Labels

    AnsibleAnsible remediation update.BashBash remediation update.OVALOVAL update. Related to the systems assessments.RHELRed Hat Enterprise Linux product related.standardsBenchmarks related.unclearSet in items where additional information is missing or exiting information is unclear.

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions