9.4 Ensure 'safRegistry' is configured

Information

The SAF user registry in the z/OS Operating System is robust and secure.

On z/OS using the native z/OS facilities like the SAF registry for authentication is recommended.

Solution

Configure the zosSecurity-1.0 feature and set the safRegistry element in ${server.config.dir}/configDropins/overrides/<any file name>.xml

<feature>zosSecurity-1.0</feature>
<safRegistry realm="myrealm" />

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2(1), CSCv7|16.2

Plugin: Unix

Control ID: 78746c53c727b10335dd102eafa79f9748959e1d30ad612e5cc16307b202ee41