5.9 DB2DOMAINLIST registry variable (Windows only)

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This registry variable is only active is the authentication parameter is set to CLIENT which is not a recommended setting as discussed in section 6.2. It is possible to have a user id be represented across multiple domains. Issues could arise when trying to authenticate such a user id. To prevent these issues, a listing of domains should be defined within the DB2DOMAINLIST registry variable.

Periodic review of the domain list assigned to the DB2DOMAINLIST registry variable helps ensure that non-essential domains do not have unnecessary authorizations.

Rationale:

Incorrectly configured DB2DOMAINLIST registry variable could result in unexpected authorization behavior where a low privileged user could potentially get access to sensitive data.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Run the following command to set the DB2DOMAINLIST registry variable to the appropriate domains:

db2set DB2_GRP_LOOKUP=<ordered list of domains separated by comma>

See Also

https://workbench.cisecurity.org/files/4033