STIGQter STIGQter: STIG Summary: IBM z/OS RACF Security Technical Implementation Guide Version: 8 Release: 3 Benchmark Date: 23 Apr 2021:

IBM z/OS, for PKI-based authentication, must use the ESM for key management.

DISA Rule

SV-223811r695458_rule

Vulnerability Number

V-223811

Group Title

SRG-OS-000068-GPOS-00036

Rule Version

RACF-SH-000060

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Define all Keys/Certificates to the security database.

Remove all .kdb and .jks key files.

Check Contents

From the ISPF Command Shell enter:
OMVS
enter
find / -name *.kdb
and
find / -name *.jks
If any files are found, this is a finding.

Vulnerability Number

V-223811

Documentable

False

Rule Version

RACF-SH-000060

Severity Override Guidance

From the ISPF Command Shell enter:
OMVS
enter
find / -name *.kdb
and
find / -name *.jks
If any files are found, this is a finding.

Check Content Reference

M

Target Key

4101

Comments