3.2.5 Limit OS Privileges of Fenced Mode Process (DB2_LIMIT_FENCED_GROUP)

Information

The DB2_LIMIT_FENCED_GROUP registry variable allows restricting the operating system privileges of the fenced mode process (db2fmp) to the privileges assigned to the DB2USERS group.

This variable only has effect if extended security is enabled (DB2_EXTSEC) and the Db2 Service Account is not LocalSystem.

This registry variable only applies to Db2 Servers running on Windows.

Rationale:

By default, the fenced mode process has access to both the DB2ADMNS and DB2USERS groups.

Solution

Run the following command to set the DB2_LIMIT_FENCED_GROUP registry variable to ON:

db2set DB2_LIMIT_FENCED_GROUP=ON

Default Value:

The default value of DB2_LIMIT_FENCED_GROUP is OFF.

See Also

https://workbench.cisecurity.org/benchmarks/10752

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Windows

Control ID: fc9a4902889181b97a33a12a5859e1f8c961d29de63a2719e877ca4e1e3d8e89