Skip to content
ATO Pathways
Log In
Overview
Search
Catalogs
SCAP
OSCAL
Catalogs
Profiles
Documents
References
Knowledge Base
Platform Documentation
Compliance Dictionary
Platform Changelog
About
Catalogs
XCCDF
Guide to the Secure Configuration of OpenEmbedded
System Settings
Kernel Configuration
Enable Yama support
Enable Yama support
An XCCDF Rule
Details
Profiles
Prose
Enable Yama support
Medium Severity
This enables support for LSM module Yama, which extends DAC support with additional system-wide security settings beyond regular Linux discretionary access controls. The module will limit the use of the system call
ptrace()
. The configuration that was used to build kernel is available at
/boot/config-*
. To check the configuration value for
CONFIG_SECURITY_YAMA
, run the following command:
grep CONFIG_SECURITY_YAMA /boot/config-*
For each kernel installed, a line with value "y" should be returned.