SV-224559r1145062_rule
V-224559
SRG-OS-000080
ZWMQ0052
CAT II
10
Review the following connection resources defined to the MQCONN resource class:
Resource Authorized Users
ssid.BATCH TSO and batch job userids
ssid.CICS CICS region userids
ssid.IMS IMS region userids
ssid.CHIN Channel initiator userids
Note: ssid is the queue manager name (a.k.a., subsystem identifier).
For all connection resources defined to the MQCONN resource class, ensure the following items are in effect:
Note: If a resource profile is not defined for a particular security check, and a user issues a request that would involve making that check, WebSphere MQ denies access.
Resource profiles are defined with a UACC(NONE).
Access authorization to these connections restricts access to the appropriate users as indicated above.
All access FAILUREs are logged.
A set of sample commands is provided below to implement the minimum profiles necessary for proper security. Note that the IMS and/or CICS profiles can be omitted if those products do not run on the target system.
/* THE FOLLOWING PROFILE FORCES GRANULAR PROFILES DEFINITIONS */
RDEF MQCONN ** UACC(NONE) OWNER(ADMIN) AUDIT(FAILURES(READ)) DATA('MQCONN DENY-BY-DEFAULT PROFILE')
RDEF MQCONN <ssid>.BATCH UACC(NONE) OWNER(ADMIN) AUDIT(FAILURES(READAUDIT(FAILURES(READ)) DATA('REQUIRED FOR ZWMQ0052')
PE <ssid>.BATCH CL(MQCONN) ID(<applicableTSO&batchUsers>)
RDEF MQCONN <ssid>.CICS UACC(NONE) OWNER(ADMIN) AUDIT(FAILURES(READ)) DATA('REQUIRED FOR ZWMQ0052')
PE <ssid>.CICS CL(MQCONN) ID(<CICSRegionUserids>)
RDEF MQCONN <ssid>.IMS UACC(NONE) OWNER(ADMIN) AUDIT(FAILURES(READ)) DATA('REQUIRED FOR ZWMQ0052')
PE <ssid>.IMS CL(MQCONN) ID(<IMSRegionUserids>)
RDEF MQCONN <ssid>.CHIN UACC(NONE) OWNER(ADMIN) AUDIT(FAILURES(READ)) DATA('REQUIRED FOR ZWMQ0052')
PE <ssid>.CHIN CL(MQCONN) ID(<WebsphereMQCHINUsrids>)
SETR RACL(MQCONN) REF
Note that an additional WebSphere MQ Refresh may be required for active queue managers. This is done from the CONSOLE:
The example is for a queue manager Named QMD1:
>QMD1 REFRESH SECURITY(*)
Refer to the following reports produced by the RACF Data Collection:
- SENSITVE.RPT(MQCONN)
Review the following connection resources for each queue manager defined to the connection resource class:
Resource Authorized Users
ssid.BATCH TSO and batch job userids
ssid.CICS CICS region userids
ssid.IMS IMS region userids
ssid.CHIN Channel initiator userids
Note: ssid is the queue manager name (a.k.a., subsystem identifier).
For all connection resources defined to the MQCONN. If the following guidance is true, this is not a finding.
Resource profiles are defined with a UACC(NONE).
Access authorization to these connections restricts access to the appropriate users as indicated above.
All access FAILUREs are logged.
V-224559
False
ZWMQ0052
Refer to the following reports produced by the RACF Data Collection:
- SENSITVE.RPT(MQCONN)
Review the following connection resources for each queue manager defined to the connection resource class:
Resource Authorized Users
ssid.BATCH TSO and batch job userids
ssid.CICS CICS region userids
ssid.IMS IMS region userids
ssid.CHIN Channel initiator userids
Note: ssid is the queue manager name (a.k.a., subsystem identifier).
For all connection resources defined to the MQCONN. If the following guidance is true, this is not a finding.
Resource profiles are defined with a UACC(NONE).
Access authorization to these connections restricts access to the appropriate users as indicated above.
All access FAILUREs are logged.
M
4167