florianutz / Ubuntu1804-CIS

Ubuntu CIS Hardening Ansible Role
MIT License
212 stars 127 forks source link

The NX||XD eventually fails on an active system #52

Open tdewitt opened 4 years ago

tdewitt commented 4 years ago


dmesg will eventually roll over and this check will fail. Using journalctl -b is slowed but will work for longer. Example from a rather vanilla install of 18.04 server:

$ dmesg | wc -l

$ journalctl -b | wc -l
umarizulkifli commented 4 years ago

According to official CIS Benchmark documents the command should be

journalctl | grep 'protection: active'