9.6 Secure the permission of the IBMLDAPSecurity.ini file

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The IBMLDAPSecurity.ini file contains the IBM LDAP security plug-in configurations.

Solution

For Windows-
1. Connect to the DB2 host
2. Right-click over the file directory
3. Choose Properties
4. Select the Security tab
5. Select all administrator accounts and grant them Read and Write authority only (revoke all others).
6. Select all non-administrator accounts and grant them Read authority only (revoke all others).
For Linux-
1. Connect to the DB2 host
2. Change to the file directory
3. Change the permission level of the directory
OS => chmod -R 664

See Also

https://workbench.cisecurity.org/files/162

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT

References: 800-53|AC-6, 800-53|CM-6, CSCv6|3.1

Plugin: Windows

Control ID: b3cb392058426ff2315f75e3035cc767180dc43f104a5f949a9aa964446d4c9a