STIGQter STIGQter: STIG Summary: IBM z/OS TSS Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

IBM z/OS for PKI-based authentication must use the ESM to store keys.

DISA Rule

SV-223883r695461_rule

Vulnerability Number

V-223883

Group Title

SRG-OS-000067-GPOS-00035

Rule Version

TSS0-ES-000100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Define all Keys/Certificates to the security database.

Remove all .kdb and .jks key files.

Check Contents

From the ISPF Command Shell enter:
OMVS
enter
find / -name *.kdb
and
Find / -name *.jks
If any files are found, this is a finding.

Vulnerability Number

V-223883

Documentable

False

Rule Version

TSS0-ES-000100

Severity Override Guidance

From the ISPF Command Shell enter:
OMVS
enter
find / -name *.kdb
and
Find / -name *.jks
If any files are found, this is a finding.

Check Content Reference

M

Target Key

4102

Comments