3.1.5 Secure default database location - DFTDBPATH set to INSTANCE_HOME

Information

The dftdbpath parameter contains the default file path used to create DB2 databases. It is recommended that this parameter is set to a directory owned by the DB2 Administrator.

Securing the default database path will ensure that the confidentiality, integrity, and availability of data contained in the DB2 service is preserved.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

1. Attach to the DB2 instance.
db2 => attach to $DB2INSTANCE
2. Run the following command from the DB2 command window:
db2 => update database manager configuration using dftdbpath

See Also

https://workbench.cisecurity.org/files/1654