8.1.5 Configure a Secure TLS Version (SSL_VERSIONS)

Information

The SSL_VERSIONS database manager configuration parameter controls which versions of the TLS protocol Db2 enables.

The versions of TLS considered secure changes over time. This recommendation will be updated to reflect those changes. Db2 12.1 supports TLS 1.2 and 1.3, both of which are considered secure. Previous versions of Db2 supported TLS 1.0 and 1.1 which are insecure and should not be used.

Solution

Perform the following to set SSL_VERSIONS :

- Attach to the Db2 instance. db2 => attach to <db2instance>
- Run the following command to enable TLS 1.3 within the Db2 server. db2 => update dbm cfg using SSL_VERSIONS TLSV13

See Also

https://workbench.cisecurity.org/benchmarks/23492

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: IBM_DB2DB

Control ID: 30d392122b53ce9e13c7b576682510ba6c23c205a0d4c287c9ed810c726e82b2