STIGQter STIGQter: STIG Summary: IBM zVM Using CA VM:Secure Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 27 Oct 2022:

IBM z/VM TCP/IP config file INTERNALCLIENTPARMS statement must be properly configured.

DISA Rule

SV-237946r859020_rule

Vulnerability Number

V-237946

Group Title

SRG-OS-000297-GPOS-00115

Rule Version

IBMZ-VM-001060

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the TCP/IP config "INTERNALCLIENTPARM" statement to include the following:

PORTNUM <secure FTP PORT Number>
SECURECONNECTION REQUIRED
CLIENTCERTCHECK FULL

Check Contents

Examine the TCP/IP config file "INTERNALCLIENTPARMS" statement.

If the following "INTERNALCLIENTPARMS" sub statement are included, this is not a finding.

PORT Num not 20 or 21
SECURECONNECTION REQUIRED
CLIENTCERTCHECK FULL

Vulnerability Number

V-237946

Documentable

False

Rule Version

IBMZ-VM-001060

Severity Override Guidance

Examine the TCP/IP config file "INTERNALCLIENTPARMS" statement.

If the following "INTERNALCLIENTPARMS" sub statement are included, this is not a finding.

PORT Num not 20 or 21
SECURECONNECTION REQUIRED
CLIENTCERTCHECK FULL

Check Content Reference

M

Target Key

5306