STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

IBM z/OS startup user account for the z/OS UNIX Telnet Server must be defined properly.

DISA Rule

SV-223639r533198_rule

Vulnerability Number

V-223639

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

ACF2-UT-000010

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the otelnetd startup command in the inetd.conf file to be defined for the z/OS UNIX kernel.

Check Contents

From the ISPF Command Shell enter:
OMVS
CD /etc
ls (to make sure OTELNET is active)
cat otelnetd.conf

If the otelnetd command specifies OMVS or OMVSKERN as the user, this is not a finding.

If the otelnetd command specifies any user other than OMVS or OMVSKERN, this is a finding.

Vulnerability Number

V-223639

Documentable

False

Rule Version

ACF2-UT-000010

Severity Override Guidance

From the ISPF Command Shell enter:
OMVS
CD /etc
ls (to make sure OTELNET is active)
cat otelnetd.conf

If the otelnetd command specifies OMVS or OMVSKERN as the user, this is not a finding.

If the otelnetd command specifies any user other than OMVS or OMVSKERN, this is a finding.

Check Content Reference

M

Target Key

4100

Comments