UCF STIG Viewer Logo

IBM Passtickets must be configured to be KeyEncrypted.


Overview

Finding ID Version Rule ID IA Controls Severity
V-257135 RACF-ES-000860 SV-257135r904403_rule Medium
Description
Passwords such as IBM Passtickets need to be protected at all times, and encryption is the standard method for protecting such passwords. If passwords are not encrypted, they may be plainly read (i.e., clear text) and easily compromised.
STIG Date
IBM z/OS RACF Security Technical Implementation Guide 2023-06-13

Details

Check Text ( C-60820r904389_chk )
From the ISPF Command Shell enter:

RList PTKTDATA * SSIGNON NORACF

If any profile is not defined as KEYENCRYPTED, this is a finding.
Fix Text (F-60761r904390_fix)
Ensure that all Passticket profiles are configured to be KeyEncrypted.