3.2.5 Limit OS Privileges of Fenced Mode Process (DB2_LIMIT_FENCED_GROUP)

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The DB2_LIMIT_FENCED_GROUP registry variable allows restricting the operating system privileges of the fenced mode process (db2fmp) to the privileges assigned to the DB2USERS group.

This variable only has effect if extended security is enabled (DB2_EXTSEC) and the Db2 Service Account is not LocalSystem.

This registry variable only applies to Db2 Servers running on Windows.

Rationale:

By default, the fenced mode process has access to both the DB2ADMNS and DB2USERS groups.

Solution

Run the following command to set the DB2_LIMIT_FENCED_GROUP registry variable to ON:

db2set DB2_LIMIT_FENCED_GROUP=ON

Default Value:

The default value of DB2_LIMIT_FENCED_GROUP is OFF.

See Also

https://workbench.cisecurity.org/files/4033