3.1.13 Enable server-based authentication

Information

The srvcon_auth parameter specifies how and where authentication is to take place for incoming connections to the server. It is recommended that this parameter is not set to CLIENT.

Solution

The recommended value is SERVER. Note- this will require a DB2 restart.
1. Attach to the DB2 instance
db2 => attach to $DB2INSTANCE
2. Run the following command from the DB2 command window-
db2 => update database manager configuration using srvcon_auth server
3. Restart the DB2 instance.
db2 => db2stop
db2 => db2start
Impact - It is important to be aware that the implementation of this recommendation results in a brief downtime. It is advisable to ensure that the setting is implemented during an approved maintenance window.

See Also

https://workbench.cisecurity.org/files/162

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2

Plugin: Unix

Control ID: 4d05e5542ddfebbb3af56625db23c5cb975236f95cc5eba695020829f5faebb3