The IBM z/VM TCP/IP configuration must include an SSLSERVERID statement.
DISA Rule
SV-237906r858945_rule
Vulnerability Number
V-237906
Group Title
SRG-OS-000033-GPOS-00014
Rule Version
IBMZ-VM-000110
Severity
CAT II
CCI(s)
- CCI-000068 - Implement cryptographic mechanisms to protect the confidentiality of remote access sessions.
- CCI-001453 - Implement cryptographic mechanisms to protect the integrity of remote access sessions.
- CCI-002448 - Distribute asymmetric cryptographic keys using: NSA-approved key management technology and processes; prepositioned keying material; DoD-approved or DoD-issued Medium Assurance PKI certificates; DoD-approved or DoD-issued Medium Hardware Assurance PKI certificates and hardware security tokens that protect the user's private key; or certificates issued in accordance with organization-defined requirements.
- CCI-002451 - Defines the systems or system components from which collaborative computing devices and applications in organization-defined secure work areas are to be disabled or removed.
- CCI-002452 - Defines the online meetings and teleconferences for which the system provides an explicit indication of current participants.
- CCI-002920 - Defines physical access controls to control access to areas within the facility designated as publicly accessible.
- CCI-003153 - Defines the locations for which to restrict information processing, information or data, and/or system services based on organization-defined requirements or conditions.
Weight
10
Fix Recommendation
Configure the "SSLSERVERID" statement to force auto logging of an SSL server before all other servers in the "AUTOLOG" list.
Check Contents
Examine the "SSLSERVERID" statement in the TCP/IP server configuration file.
If the "SSLSERVERID" statement identifies at least one userID for an SSL server, this is not a finding.
Vulnerability Number
V-237906
Documentable
False
Rule Version
IBMZ-VM-000110
Severity Override Guidance
Examine the "SSLSERVERID" statement in the TCP/IP server configuration file.
If the "SSLSERVERID" statement identifies at least one userID for an SSL server, this is not a finding.
Check Content Reference
M
Target Key
5306