1.4 Use non-default account names

Information

The DB2 service is installed with default accounts with well-known names such as db2admin, db2inst1, dasusr1, or db2fenc1. It is recommended that the use of these account names be avoided. The default accounts may be renamed and then used.

The use of default accounts may increase the DB2 service's susceptibility to unauthorized access by an attacker.

Solution

For Windows:
1. Right-click over the %DB2PATH% and select Properties from the menu.
2. Go to the Security tab and re-assign all the user accounts with well-known default names to use non-default names.
For Linux, perform the following command:
chown -R <new user name>:<new group name> $DB2PATH
Notes:
Review the impact of changing the usernames before performing this global change.

See Also

https://workbench.cisecurity.org/files/1654

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2f.

Plugin: Windows

Control ID: 34a5ef18589d83d3d753f87f8a4634858fa9ad4477bb67af789e9e3aa3fb69bf