IBM Support

OA49545: COMPLIANCE CHECK FOR STIG RULE ZWMQ0059 IS INCORRECT.

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • The Channel Initiator started task, which resides in the MQCI
    subsystem, needs the ability to issue MQ Commands. Our
    compliance check for ZWMQ0059 currently marks this as
    non-compliant.
    

Local fix

  • Not Applicable
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: Users of zSecure Audit exploiting STIG       *
    *                 compliance rules ZWMQ0040 and ZWMQ0059.      *
    ****************************************************************
    * PROBLEM DESCRIPTION: The zSecure Audit STIG compliance rules *
    *                      ZWMQ0040 and ZWMQ0059 might produce     *
    *                      incorrect results.                      *
    ****************************************************************
    * RECOMMENDATION: Apply the PTF provided.                      *
    ****************************************************************
    The zSecure Audit STIG rules ZWMQ0040 (All update and and alter
    access to MQ product and system data sets must be properly
    restricted) and ZWMQ0059 (IBM MQ for z/OS command resources must
    be protected in class MQCMDS) might report a non-compliance for
    the MQ Channel Initiator started task for resources that it
    needs.
    

Problem conclusion

  • zSecure Audit has been modified so that STIG rules ZWMQ0040 and
    ZWMQ0059 take the access needed by the MQ Channel Initiator into
    account.
    211Y
    220Y
    CKAGWM40
    CKAGWM59
    

Temporary fix

Comments

APAR Information

  • APAR number

    OA49545

  • Reported component name

    ZSEC BASE,ADMIN

  • Reported component ID

    5655T0100

  • Reported release

    211

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2015-12-09

  • Closed date

    2016-01-28

  • Last modified date

    2016-02-01

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UA80483 UA80484

Modules/Macros

  •    CKAGWM40 CKAGWM59
    

Fix information

  • Fixed component name

    ZSEC BASE,ADMIN

  • Fixed component ID

    5655T0100

Applicable component levels

  • R211 PSY UA80483

       UP16/01/29 P F601

  • R220 PSY UA80484

       UP16/01/29 P F601

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU048","label":"IBM Software"}, "Product":{"code":"SSCE68R","label":"zSecure Admin"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"211","Edition":""}]

Document Information

Modified date:
01 February 2016