STIGQter STIGQter: STIG Summary: IBM zVM Using CA VM:Secure Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 27 Oct 2022:

The IBM z/VM TCP/IP Key database for LDAP or SSL server must be created with the proper permissions.

DISA Rule

SV-237910r858954_rule

Vulnerability Number

V-237910

Group Title

SRG-OS-000067-GPOS-00035

Rule Version

IBMZ-VM-000470

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure proper permissions are assigned to key databases.

Issue the "OPENVM PERMIT" commands to assign proper permissions.

Check Contents

Issue command openvm list /etc./gskadm/ (own)

If the file permissions are as displayed below, this is not a finding.

User ID Group Name Permissions Type Path name component

gskadmin security rw- r-- --- F 'Database.kdb'

gskadmin security rw- --- --- F 'Database.rdb'

gskadmin security rw- r-- --- F 'Database.sth'

Vulnerability Number

V-237910

Documentable

False

Rule Version

IBMZ-VM-000470

Severity Override Guidance

Issue command openvm list /etc./gskadm/ (own)

If the file permissions are as displayed below, this is not a finding.

User ID Group Name Permissions Type Path name component

gskadmin security rw- r-- --- F 'Database.kdb'

gskadmin security rw- --- --- F 'Database.rdb'

gskadmin security rw- r-- --- F 'Database.sth'

Check Content Reference

M

Target Key

5306