STIGQter STIGQter: STIG Summary: IBM z/OS TSS Security Technical Implementation Guide Version: 9 Release: 9 Benchmark Date: 01 Jul 2026:

All IBM z/OS digital certificates in use must have a valid path to a trusted Certification Authority (CA).

DISA Rule

SV-223871r998483_rule

Vulnerability Number

V-223871

Group Title

SRG-OS-000066-GPOS-00034

Rule Version

TSS0-CE-000010

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove or replace certificates where the issuer's distinguished name does not lead to a DOD PKI Root Certification Authority; External Root Certification Authority (ECA); or an approved External Partner PKI's Root Certification Authority.

The DOD Cyber Exchange website contains information as to which certificates may be acceptable (https://public.cyber.mil/pki-pke/interoperability/ or https://cyber.mil/pki-pke/interoperability/).

Check Contents

Execute the CA-TSS SAFCRRPT using the following as SYSIN input:
RECORDID(-) DETAIL TRUST FIELDS(ISSUER SUBJECT ACTIVE EXPIRE TRUST)

If no certificate information is found, this is not a finding.

NOTE: Certificates are only valid when their Status is TRUST. Therefore, you may ignore certificates with the NOTRUST status during the following check.

If the digital certificate information indicates that the issuer's distinguished name leads to one of the following this is not a finding:
a) A DOD PKI Root Certification Authority
b) An External Root Certification Authority (ECA)
c) An approved External Partner PKI's Root Certification Authority

The DOD Cyber Exchange website contains information as to which certificates may be acceptable (https://public.cyber.mil/pki-pke/interoperability/ or https://cyber.mil/pki-pke/interoperability/).

Examples of an acceptable DOD CA are:
DOD PKI Class 3 Root CA
DOD PKI Med Root CA

Vulnerability Number

V-223871

Documentable

False

Rule Version

TSS0-CE-000010

Severity Override Guidance

Execute the CA-TSS SAFCRRPT using the following as SYSIN input:
RECORDID(-) DETAIL TRUST FIELDS(ISSUER SUBJECT ACTIVE EXPIRE TRUST)

If no certificate information is found, this is not a finding.

NOTE: Certificates are only valid when their Status is TRUST. Therefore, you may ignore certificates with the NOTRUST status during the following check.

If the digital certificate information indicates that the issuer's distinguished name leads to one of the following this is not a finding:
a) A DOD PKI Root Certification Authority
b) An External Root Certification Authority (ECA)
c) An approved External Partner PKI's Root Certification Authority

The DOD Cyber Exchange website contains information as to which certificates may be acceptable (https://public.cyber.mil/pki-pke/interoperability/ or https://cyber.mil/pki-pke/interoperability/).

Examples of an acceptable DOD CA are:
DOD PKI Class 3 Root CA
DOD PKI Med Root CA

Check Content Reference

M

Target Key

4102