3.1.16 Enable server-based authentication

Information

The srvcon_auth parameter specifies how and where authentication is to take for incoming connections to the server. It is recommended that this parameter is not set to CLIENT.

This parameter will take precedence over and override the authentication level. Authentication should be set on the server side.

Solution

The recommended value is SERVER. Note: this will require a DB2 restart.
1. Attach to the DB2 instance.
db2 => attach to $DB2INSTANCE
2. Run the following command from the DB2 command window:
db2 => update database manager configuration using srvcon_auth server
3. Restart the DB2 instance.
db2 => db2stop
db2 => db2start
Impact:
The implementation of this recommendation results in a brief downtime. It is advisable to ensure that the setting is implemented during an approved maintenance window.
Default Value:
The default value for SRVCON_AUTH is NULL.

See Also

https://workbench.cisecurity.org/files/1654

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2

Plugin: IBM_DB2DB

Control ID: d3073550029290698ad3328f591c982fbf6399445dbcd1f1456543081c893992