STIGQter STIGQter: STIG Summary: IBM z/OS RACF Security Technical Implementation Guide Version: 9 Release: 9 Benchmark Date: 01 Jul 2026:

IBM Passtickets must be configured to be KeyEncrypted.

DISA Rule

SV-257135r998383_rule

Vulnerability Number

V-257135

Group Title

SRG-OS-000073-GPOS-00041

Rule Version

RACF-ES-000860

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure that all Passticket profiles are configured to be KeyEncrypted.

Check Contents

From the ISPF Command Shell enter:

RList PTKTDATA * SSIGNON NORACF

If any profile is not defined as KEYENCRYPTED, this is a finding.

Vulnerability Number

V-257135

Documentable

False

Rule Version

RACF-ES-000860

Severity Override Guidance

From the ISPF Command Shell enter:

RList PTKTDATA * SSIGNON NORACF

If any profile is not defined as KEYENCRYPTED, this is a finding.

Check Content Reference

M

Target Key

4101