UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

CA 1 Tape Management system password will be changed from the default.


Overview

Finding ID Version Rule ID IA Controls Severity
V-224448 ZCA10041 SV-224448r868298_rule Medium
Description
CA 1 Tape Management default system password is common with all CA 1 systems. With this password, CA 1 tape processing can be deactivated. This could allow for unauthorized access to information stored on tape volumes and the CA 1 Tape Management Catalog (TMC). The result may threaten the integrity and availability of the CA 1 Tape Management System, and compromise the confidentiality of customer data.
STIG Date
z/OS CA 1 Tape Management for RACF Security Technical Implementation Guide 2022-10-07

Details

Check Text ( C-26125r868296_chk )
Refer to the following report produced by the z/OS Data Collection:

- CA1RPT(TMSTMVT) - for r11.5 and below
- CA1RPT(TMOOPTxx) - for r12.0 and above

Automated Analysis
Refer to the following report produced by the z/OS Data Collection:

- PDI(ZCA10041)

For r11.5 and below refer to offset x'18' from the beginning of module TMSTMVT. For r12.0 and above refer to the SHUTDWN option specified in the TMOOPTxx. The TMOOPTxx member is specified in the TMOSYSxx member in the data set allocated by the TMSPARM DD statement in the TMSINIT STC. If the default CA 1 system password is not being utilized, this is not a finding.

NOTE: The default system password for CA 1 provided by CA is CA1(TMS). The default system passwords provided by SSO are SSOCA1DF and SSOC@1DF.
Fix Text (F-26113r868297_fix)
The systems programmer/ISSO will ensure that the CA 1 system password is changed from the vendor default system password.

Verify upon installation that the password is not the same as the default password and user distributed with the original installation default.

For r11.5 and below refer to offset x'18' from the beginning of module TMSTMVT.

For r12.0 and above refer to the SHUTDWN option specified in the TMOOPTxx. The TMOOPTxx member is specified in the TMOSYSxx member in the data set allocated by the TMSPARM DD statement in the TMSINIT STC.

NOTE: The default system password for CA 1 provided by CA is CA1(TMS). The default system passwords provided by SSO are SSOCA1DF and SSOC@1DF.