8.1.11 Enable Remote TLS Connections to Db2 (DB2COMM)

Information

The DB2COMM registry variable controls what types of remote connections Db2 will accept. It can be configured to enable plaintext communication, encrypted communication, or both.

Rationale:

For security, DB2COMM should be set to enable only TLS encrypted communications.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Perform the following to set DB2COMM and enable TLS:

Run the following command as the instance owner.

db2set DB2COMM=SSL

Db2 must be recycled (db2stop/db2start) for changes to the DB2COMM registry variable to take effect.

See Also

https://workbench.cisecurity.org/benchmarks/10752

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: Windows

Control ID: 861e1000338bdc68ee5d6652dba0950a1555326498c306a9a40b30fa3219e438