STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 2 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to IBM MQ Appliance V9.0 AS Security Technical Implementation Guide

V-255794

CAT III (Low)

The MQ Appliance messaging server must accept FICAM-approved third-party credentials.

Rule ID

SV-255794r981695_rule

STIG

IBM MQ Appliance V9.0 AS Security Technical Implementation Guide

Version

V1R2

CCIs

CCI-002011CCI-002014

Discussion

Access may be denied to legitimate users if FICAM-approved third-party credentials are not accepted. This requirement typically applies to organizational information systems that are accessible to non-federal government agencies and other partners. This allows federal government relying parties to trust such credentials at their approved assurance levels. Third-party credentials are those credentials issued by non-federal government entities approved by the Federal Identity, Credential, and Access Management (FICAM) Trust Framework Solutions initiative. Satisfies: SRG-APP-000404-AS-000249, SRG-APP-000405-AS-000250

Check Content

Log on to the WebGUI as a privileged user.

Click on the "MQ Console" icon.

Click "Add" widget at the top right of the screen.

Select queue manager intended for OCSP from the drop-down list.

Select "Authentication Information".

Verify that the authentication type is "OCSP".

Click on the "Properties" button.

Click "OCSP" on the side bar to verify that the OCSP responder URL is correct.

If either the authentication type is not "OCSP" or the OCSP responder URL in not correct, this is a finding.

Fix Text

Log on to the WebGUI as a privileged user.

Click on the "MQ Console" icon.

Click "Add" widget at the top right of the screen.

Select a queue manager from the drop-down list.

Select "Authentication Information".

Click the "+" (plus sign) to define the authentication method authentication for this queue manager.

Specify an "Authinfo" name (e.g., USE.OCSP).

Select "OCSP" as the "Authinfo" type.

Specify an OCSP responder URL.

Click "Create".

In the "Local Queue Managers" widget, select the OCSP queue manager you just configured.

Click "More..." then select "Refresh Security... "