IBM Support

OA67560: ZWMQ0053 REPORTS INCORRECT NON-COMPLIANT FINDING WHEN DISPLAY QMGR DEADQ RETURNS ONLY THE ALIAS DEAD LETTER QUEUE NAME

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • ZWMQ0053 reports incorrect non-compliant finding when DISPLAY
    QMGR DEADQ returns only the alias dead letter queue name.
    
    The ZWMQ0053_RDLQ rule determines non-compliance because the
    control only has information about the alias dead letter queue
    and not the real dead letter queue.
    

Local fix

  • N/A
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: Users of zSecure Audit exploiting the STIG   *
    *                 compliance control ZWMQ0053.                 *
    ****************************************************************
    * PROBLEM DESCRIPTION: zSecure Audit's STIG compliance control *
    *                      ZWMQ0053 might report incorrect         *
    *                      non-compliant results.                  *
    ****************************************************************
    * RECOMMENDATION: Apply the PTF provided and review the        *
    *                 documentation updates.                       *
    ****************************************************************
    The STIG compliance control ZWMQ0053 (IBM MQ for z/OS
    dead-letter and alias dead-letter queues must be properly
    defined) might incorrectly report non-compliant results in cases
    where the dead letter queue security is configured in accordance
    to the IBM MQ recommendations for dead-letter queue security
    where applications can only access the dead-letter queue through
    an alias queue.
    

Problem conclusion

  • zSecure Audit has been modified, so that the STIG compliance
    control ZWMQ0053 does not report non-compliant finding in cases
    where he IBM MQ dead-letter queue access is configured through
    an alias queue. Please note the documentation changes as
    provided by the APAR tracking comment data.
    

Temporary fix

Comments

APAR Information

  • APAR number

    OA67560

  • Reported component name

    ZSEC BASE,ADMIN

  • Reported component ID

    5655T0100

  • Reported release

    310

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2025-02-25

  • Closed date

    2025-03-31

  • Last modified date

    2025-04-02

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UJ96909

Modules/Macros

  • C2R3MQ2I C2RHWM53 CKAFDMQ  CKAOUMQR CKRINLT  CKRINMO  GKRFDMQ
    GKRINLT  GKRINMO  GKROUMQR
    

Fix information

  • Fixed component name

    ZSEC BASE,ADMIN

  • Fixed component ID

    5655T0100

Applicable component levels

  • R310 PSY UJ96909

       UP25/04/01 P F503

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSPQTM","label":"IBM Security zSecure Admin"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"310","Line of Business":{"code":"LOB70","label":"Z TPS"}}]

Document Information

Modified date:
02 April 2025