3.1.2 Encrypt user data across the network

Information

DB2 supports a number of authentication mechanisms. It is recommended that the DATA_ENCRYPT authentication mechanism be used.

The DATA_ENCRYPT authentication mechanism employs cryptographic algorithms to protect the confidentiality of authentication credentials and user data as they traverse the network between the DB2 client and server.

Solution

The suggested value is DATA_ENCRYPT so that authentication occurs at the server. To set this:
1. Attach to the DB2 instance:
db2 => attach to $DB2INSTANCE
2. Run the following command from the DB2 command window:
db2 => update database manager configuration using authentication data_encrypt
Default Value:
The default value for AUTHENTICATION is SERVER.

See Also

https://workbench.cisecurity.org/files/1654

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8(1)

Plugin: Windows

Control ID: 38fca1c1f31b3df9ae644af4b824bbed3e9776e608ca5234a93eaa0f54ff099d