STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 2 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to IBM MQ Appliance V9.0 AS Security Technical Implementation Guide

V-255797

CAT II (Medium)

The MQ Appliance messaging server must uniquely identify all network-connected endpoint devices before establishing any connection.

Rule ID

SV-255797r1000054_rule

STIG

IBM MQ Appliance V9.0 AS Security Technical Implementation Guide

Version

V1R2

CCIs

CCI-000778

Discussion

Without identifying devices, unidentified or unknown devices may be introduced, thereby facilitating malicious activity. For distributed messaging servers and components, the decisions regarding the validation of identification claims may be made by services separate from the messaging server. In such situations, it is necessary to provide the identification decisions (as opposed to the actual identifiers) to the services that need to act on those decisions. Note: Following are the cipher specs available for MQ: https://ibm.biz/BdrJGp

Check Content

Check that TLS mutual authentication configuration is correct by using "DISPLAY" commands. 

To access the MQ Appliance CLI, enter:
mqcli

To identify the queue managers, enter:
dspmq

For each queue manager identified, run the command:
runmqsc [queue name]

To display available SVRCONN channels details, enter:
DIS CHANNEL(*) CHLTYPE(SVRCONN)

Note the names of SVRCONN channels (client channels). 

Display values for each channel:
DIS CHANNEL([name of SVRCONN channel])

Confirm that the parameter "SSLCIPH" specifies a FIPS approved cipher spec and that the value of "SSLAUTH" is set to "REQUIRED".

MQ cipher specs are available here: https://ibm.biz/BdrJGp Utilize a FIPS approved cipher when specifying SSLCIPH.

If either the "SSLCIPH" or "SSLAUTH" value for each channel is not correct, this is a finding.

Fix Text

Run the fix for each affected queue manager and each affected channel. 

To access the MQ Appliance enter:
mqcli
runmqsc [queue name]

ALTER CHANNEL([channel name] CHLTYPE(SVRCONN) TRPTYPE(TCP) 
SSLCIPH([Use FIPS Approved cipher specs only]) SSLCAUTH(REQUIRED)

Enter "end" to exit runmqsc mode.