SV-224557r1145056_rule
V-224557
SRG-OS-000080
ZWMQ0049
CAT II
10
Ensure that all WebSphere MQ resources are active and properly defined.
Ensure the following WebSphere MQ resource classes are active:
GMQADMIN
GMQNLIST
GMQPROC
GMQQUEUE
MQADMIN
MQCMDS
MQCONN
MQNLIST
MQPROC
MQQUEUE
When SCYCASE is set to mixed, CLASMAP Definitions must include the following entries:
GMXADMIN
GMXNLIST
GMXPROC
GMXQUEUE
GMXTOPIC
MXADMIN
MXNLIST
MXPROC
MXQUEUE
MXTOPIC
Note: If MQADMIN or MXADMIN resource classes are not active, no security checking is performed.
The following sample contains commands to activate the required classes:
SETR CLASSACT(MQADMIN MQCMDS MQCONN)
SETR CLASSACT(MQNLIST MQPROC MQQUEUE)
SETR CLASSACT(MXADMIN MXNLIST MXPROC MXQUEUE)
Refer to the following reports produced by the RACF Data Collection:
- RACFCMDS.RPT(SETROPTS)
- DSMON.RPT(RACCDT) - Alternate list of active resource classes
Automated Analysis
Refer to the following report produced by the RACF Data Collection:
- PDI(ZWMQ0049)
Verify the following WebSphere MQ resource classes are active, this is not a finding.
GMQADMIN
GMQNLIST
GMQPROC
GMQQUEUE
MQADMIN
MQCMDS
MQCONN
MQNLIST
MQPROC
MQQUEUE
If SCYCASE is set to MIXED, ensure the following WebSphere MQ resource classes are active, this is not a finding.
GMXADMIN
GMXNLIST
GMXPROC
GMXQUEUE
GMXTOPIC
MXADMIN
MXNLIST
MXPROC
MXQUEUE
MXTOPIC
Note: If MQADMIN or MXADMIN resource classes are not active, no security checking is performed.
V-224557
False
ZWMQ0049
Refer to the following reports produced by the RACF Data Collection:
- RACFCMDS.RPT(SETROPTS)
- DSMON.RPT(RACCDT) - Alternate list of active resource classes
Automated Analysis
Refer to the following report produced by the RACF Data Collection:
- PDI(ZWMQ0049)
Verify the following WebSphere MQ resource classes are active, this is not a finding.
GMQADMIN
GMQNLIST
GMQPROC
GMQQUEUE
MQADMIN
MQCMDS
MQCONN
MQNLIST
MQPROC
MQQUEUE
If SCYCASE is set to MIXED, ensure the following WebSphere MQ resource classes are active, this is not a finding.
GMXADMIN
GMXNLIST
GMXPROC
GMXQUEUE
GMXTOPIC
MXADMIN
MXNLIST
MXPROC
MXQUEUE
MXTOPIC
Note: If MQADMIN or MXADMIN resource classes are not active, no security checking is performed.
M
4167