STIGQter STIGQter: STIG Summary: IBM z/OS TSS Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

IBM z/OS must use NIST FIPS-validated cryptography to protect passwords in the security database.

DISA Rule

SV-223887r561402_rule

Vulnerability Number

V-223887

Group Title

SRG-OS-000073-GPOS-00041

Rule Version

TSS0-ES-000140

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Evaluate the impact associated with implementation of the control option.

Develop a plan of action to implement the control option as specified below:

Convert passwords/password phrases from Triple-DES encryption to 128-bit AES or 256-bit encryption by running TSSMAINT (with the AESENCRYPT option specified) and then running TSSXTEND to copy the old security file to the new security file.

Please consult CA-TSS Installation guide for more information.

Check Contents

From the ISPF command shell line enter:
TSS MODIFY(STATUS)

If either of the following is included, this is not a finding.

AES_ENCRYPTION(Active,128)
AES_ENCRYPTION(Active,256)

Vulnerability Number

V-223887

Documentable

False

Rule Version

TSS0-ES-000140

Severity Override Guidance

From the ISPF command shell line enter:
TSS MODIFY(STATUS)

If either of the following is included, this is not a finding.

AES_ENCRYPTION(Active,128)
AES_ENCRYPTION(Active,256)

Check Content Reference

M

Target Key

4102

Comments