3.1.18 Reserve the desired port number or name for incoming SSL connections

Information

The ssl_ssl_svcename configuration parameter defines the name or number of the port the database server listens for incoming communications from remote client nodes using the SSL protocol. The ssl_ssl_svcename and ssl_svcename port numbers cannot be the same.
On Linux operating systems, the ssl_ssl_svcename file is located in: /etc/services

Consider using a non-default port to help protect the database from attacks directed to a default port.

Solution

Run the following command to set the ssl_ssl_svcename parameter value.
db2 => update dbm cfg using ssl_ssl_svcename <value> immediate or deferred
Default Value:
Null

See Also

https://workbench.cisecurity.org/files/1654

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|3.1

Plugin: Windows

Control ID: c5137c3c60476e70a7b255cf81c3f252c7028f1d743a1ebec69cf186f77c77f4