IBM Support

OA58747: RACF STIG CONTROLS RACF0310 AND RACF0320 DO NOT EXEMPT THE CFIELD AND IDIDMAP CLASSES

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • RACF STIG controls RACF0310 and RACF0320 do not exempt the
    CFIELD and IDIDMAP classes.
    

Local fix

  • N/A
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: Users of zSecure Audit compliance testing    *
    *                 framework exploiting STIG compliance rules   *
    *                 RACF0310 and RACF0320.                       *
    ****************************************************************
    * PROBLEM DESCRIPTION: The zSecure Audit STIG compliance rules *
    *                      RACF0310 and RACF0320 produces false    *
    *                      non-compliant results for the CFIELD    *
    *                      and IDIDMAP classes.                    *
    ****************************************************************
    * RECOMMENDATION: Apply the PTF provided.                      *
    ****************************************************************
    The results that the STIG compliance rules RACF0310 (The GENCMD
    SETROPTS value should be enabled for ACTIVE classes) and
    RACF0320 (The GENERIC SETROPTS value should be enabled for
    ACTIVE classes) generate do not exempt the CFIELD and IDIDMAP
    classes so causing that compliance reports potentially include
    inaccurate  non-compliant results for these classes.
    

Problem conclusion

  • zSecure Audit has been modified so that the STIG rules RACF0310
    and RACF0320 exempts the CFIELD and IDIDMAP classes.
    

Temporary fix

Comments

APAR Information

  • APAR number

    OA58747

  • Reported component name

    ZSEC BASE,ADMIN

  • Reported component ID

    5655T0100

  • Reported release

    231

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2019-11-28

  • Closed date

    2019-12-06

  • Last modified date

    2020-01-03

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UJ01540 UJ01541

Modules/Macros

  • CKAGR310 CKAGR320
    

Fix information

  • Fixed component name

    ZSEC BASE,ADMIN

  • Fixed component ID

    5655T0100

Applicable component levels

  • R231 PSY UJ01540

       UP19/12/10 P F912

  • R240 PSY UJ01541

       UP19/12/10 P F912

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU048","label":"IBM Software"}, "Product":{"code":"SSCE68R","label":"zSecure Admin"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"231","Edition":""}]

Document Information

Modified date:
03 January 2020