8.2.4 Secure the Stash File


A stash file is an obfuscated file that contains the credentials that are needed to access the keystore. If a keystore password was not provided during db2start, the password will be retrieved from the stash file.

A stash file is created when -stash command is used during the creation of the keystore.


Set this file to be readable by only the Db2 instance owner. If this file is not secured, an attacker may delete it, causing potential interruption of operations.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.


Change the permissions for the file:

$ chmod 600 keystore.sth

See Also
