A fix is available
APAR status
Closed as program error.
Error description
ZWMQ0053 reports incorrect non-compliant finding when DISPLAY QMGR DEADQ returns only the alias dead letter queue name. The ZWMQ0053_RDLQ rule determines non-compliance because the control only has information about the alias dead letter queue and not the real dead letter queue.
Local fix
N/A
Problem summary
**************************************************************** * USERS AFFECTED: Users of zSecure Audit exploiting the STIG * * compliance control ZWMQ0053. * **************************************************************** * PROBLEM DESCRIPTION: zSecure Audit's STIG compliance control * * ZWMQ0053 might report incorrect * * non-compliant results. * **************************************************************** * RECOMMENDATION: Apply the PTF provided and review the * * documentation updates. * **************************************************************** The STIG compliance control ZWMQ0053 (IBM MQ for z/OS dead-letter and alias dead-letter queues must be properly defined) might incorrectly report non-compliant results in cases where the dead letter queue security is configured in accordance to the IBM MQ recommendations for dead-letter queue security where applications can only access the dead-letter queue through an alias queue.
Problem conclusion
zSecure Audit has been modified, so that the STIG compliance control ZWMQ0053 does not report non-compliant finding in cases where he IBM MQ dead-letter queue access is configured through an alias queue. Please note the documentation changes as provided by the APAR tracking comment data.
Temporary fix
Comments
APAR Information
APAR number
OA67560
Reported component name
ZSEC BASE,ADMIN
Reported component ID
5655T0100
Reported release
310
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2025-02-25
Closed date
2025-03-31
Last modified date
2025-04-02
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
UJ96909
Modules/Macros
C2R3MQ2I C2RHWM53 CKAFDMQ CKAOUMQR CKRINLT CKRINMO GKRFDMQ GKRINLT GKRINMO GKROUMQR
Fix information
Fixed component name
ZSEC BASE,ADMIN
Fixed component ID
5655T0100
Applicable component levels
R310 PSY UJ96909
UP25/04/01 P F503
Fix is available
Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.
[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSPQTM","label":"IBM Security zSecure Admin"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"310","Line of Business":{"code":"LOB70","label":"Z TPS"}}]
Document Information
Modified date:
02 April 2025