This commit is contained in:
Patrick Schleizer 2020-04-13 06:56:34 -04:00
parent 253578afdf
commit e0b8640fb9
No known key found for this signature in database
GPG Key ID: CB8D50BB77BB3C48

View File

@ -158,8 +158,9 @@ Alternatively file `/usr/local/etc/remount-disable` or file
`/lib/systemd/system/remount-secure.service`
`/usr/lib/security-misc/remount-secure`
* A systemd service mounts `/proc` with `hidepid=2` at boot to prevent users
from seeing each other's processes.
* An optional systemd service mounts `/proc` with `hidepid=2` at boot to
prevent users from seeing each other's processes. Not enabled because not
compatible with pkexec.
* The kernel logs are restricted to root only.