UCF STIG Viewer Logo

IBM z/OS UNIX Telnet Server warning banner must be properly specified.


Overview

Finding ID Version Rule ID IA Controls Severity
V-223642 ACF2-UT-000040 SV-223642r864508_rule Medium
Description
Display of a standardized and approved use notification before granting access to the publicly accessible operating system ensures privacy and security notification verbiage used is consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance. System use notifications are required only for access via logon interfaces with human users and are not required when such human interfaces do not exist.
STIG Date
IBM z/OS ACF2 Security Technical Implementation Guide 2022-12-14

Details

Check Text ( C-25315r501063_chk )
From the ISPF Command Shell enter:
OMVS
cat inetd.conf

If the otelnet startup command includes option "-h", this is a finding.
Fix Text (F-25303r501064_fix)
The otelnetd startup command should not include the option "-h", where:

-h indicates that the logon banner should not be displayed.