UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

IBM Passtickets must be configured to be KeyEncrypted.


Overview

Finding ID Version Rule ID IA Controls Severity
V-257135 RACF-ES-000860 SV-257135r998383_rule Medium
Description
Passwords such as IBM Passtickets need to be protected at all times, and encryption is the standard method for protecting such passwords. If passwords are not encrypted, they may be plainly read (i.e., clear text) and easily compromised.
STIG Date
IBM z/OS RACF Security Technical Implementation Guide 2024-06-24

Details

Check Text ( C-60820r904389_chk )
From the ISPF Command Shell enter:

RList PTKTDATA * SSIGNON NORACF

If any profile is not defined as KEYENCRYPTED, this is a finding.
Fix Text (F-60761r904390_fix)
Ensure that all Passticket profiles are configured to be KeyEncrypted.