9.6 Secure the permission of the IBMLDAPSecurity.ini file

Information

The IBMLDAPSecurity.ini file contains the IBM LDAP security plug-in configurations.

Solution

For Windows-
1. Connect to the DB2 host
2. Right-click over the file directory
3. Choose Properties
4. Select the Security tab
5. Select all administrator accounts and grant them Read and Write authority only (revoke all others).
6. Select all non-administrator accounts and grant them Read authority only (revoke all others).
For Linux-
1. Connect to the DB2 host
2. Change to the file directory
3. Change the permission level of the directory
OS => chmod -R 664

See Also

https://workbench.cisecurity.org/files/162