3.1.8 Require instance name for discovery requests

Information

The discover parameter determines what kind of discovery requests, if any, the DB2 server will fulfill. It is recommended that the DB2 server only fulfill requests from clients that know the given instance name (discover parameter value of known).

Solution

The recommended value is KNOWN. Note- this requires a DB2 restart.
1. Attach to the DB2 instance
db2 => attach to $DB2INSTANCE
2. Run the following command from the DB2 command window-
db2 => update database manager configuration using discover known
3. Restart the DB2 instance.
db2 => db2stop
db2 => db2start
Impact-
It is important to be aware that the implementation of this recommendation results in a brief downtime. It is advisable to ensure that the setting is implemented during an approved maintenance window.

See Also

https://workbench.cisecurity.org/files/162

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|3.1

Plugin: Unix

Control ID: 080c9b8fc5f5f0c9eee8554c63156563900965be33ac2fbdd1dda48189023122