Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-78889 | IBMZ-VM-000680 | SV-93595r1_rule | Medium |
Description |
---|
Operating systems utilizing encryption are required to use FIPS-compliant mechanisms for authenticating to cryptographic modules. |
STIG | Date |
---|---|
IBM z/VM Using CA VM:Secure Security Technical Implementation Guide | 2018-04-04 |
Check Text ( C-78475r1_chk ) |
---|
If there is no FTP Server active, this is not applicable. Examine the “DTCPARMS” file for each active FTP server. If there is “:ANONYMOUS” or “:ANONYMOU” statement, this is a finding. Examine the “SRVRFTP” command. If “ANONYMOU” is coded, this is a finding. |
Fix Text (F-85639r1_fix) |
---|
Ensure the “:ANONYMOUS” or “:ANONYMOU” statement is not coded in the “DTCPARMS” or “SRVRFTP” command. |