9.7 Secure the permission of the SSLconfig.ini file

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The SSLconfig.ini file contains the SSL configuration parameters for the DB2 instance, including the password for KeyStore.

Solution

For Windows-
1. Connect to the DB2 host
2. Right-click over the file directory
3. Choose Properties
4. Select the Security tab
5. Select all administrator accounts and grant them the Full Control authority
6. Select the SYSADM group and grant it Read and Write authority only (revoke all others)
7. Select all other accounts and revoke all privileges to the directory
For Unix-
1. Connect to the DB2 host
2. Change to the file directory
3. Change the permission level of the directory
OS => chmod -R 760

See Also

https://workbench.cisecurity.org/files/162

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT

References: 800-53|AC-6, 800-53|CM-6, CSCv6|3.1

Plugin: Windows

Control ID: 5e424b3fe1fd5801fd2e237901f2fb4d702ea6da09f2b7fd8275bae0ec4139bd