STIGQter STIGQter: STIG Summary: IBM z/OS TSS Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

The CA-TSS NEWPHRASE and PPSCHAR Control Options must be properly set.

DISA Rule

SV-223885r561402_rule

Vulnerability Number

V-223885

Group Title

SRG-OS-000069-GPOS-00037

Rule Version

TSS0-ES-000120

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Note: Support of mixed case passwords can only be set when the security file has been copied by TSSXTEND with the option NEWPWBLOCK.

Configure the NEWPHRASE Control Option values to the following requirements:

MA=1-32
MN=1-32
ID
MAX=100
MIN=15-100
MINDAYS=1
NR=0-1
SC=1-32
WARN=1-10

Configure the PPSCHAR Control Option to the allowable list defined in CA Top Secret for z/OS User Guide.

Note: These characters will be specified at a minimum. ‘40’ represents the blank character. Characters can be identified by their character or hex equivalent.

Example:

TSS MODIFY NEWPHRASE(MA=1,MN=1,ID,MAX=100,MIN=15,MINDAYS=1,NR=1,SC=1,WARN=10)
TSS MODIFY PPSCHAR(c,c,c,c,...)

(Use the allowable list defined in CA Top Secret for z/OS Control Options Guide.)

Check Contents

From the ISPF Command Shell enter:
TSS MODIFY STATUS

If the NEWPHRASE Control Option conforms to the following requirements, this is not a finding.

MA=1-32
MN=1-32
ID
MAX=100
MIN=15-100
MINDAYS=1
NR=0-1
SC=1-32
WARN=1-10

If the PPSCHAR Control Option conform to the allowable list defined in CA Top Secret for z/OS Control Options Guide, this is not a finding.

Note: These characters will be specified at a minimum. "40" represents the blank character. Characters can be identified by their character or hex equivalent.

Vulnerability Number

V-223885

Documentable

False

Rule Version

TSS0-ES-000120

Severity Override Guidance

From the ISPF Command Shell enter:
TSS MODIFY STATUS

If the NEWPHRASE Control Option conforms to the following requirements, this is not a finding.

MA=1-32
MN=1-32
ID
MAX=100
MIN=15-100
MINDAYS=1
NR=0-1
SC=1-32
WARN=1-10

If the PPSCHAR Control Option conform to the allowable list defined in CA Top Secret for z/OS Control Options Guide, this is not a finding.

Note: These characters will be specified at a minimum. "40" represents the blank character. Characters can be identified by their character or hex equivalent.

Check Content Reference

M

Target Key

4102

Comments