Enable db2 to use SVCENAME only as a resync port, not allowing connections to this port

We expect that credentials are properly secured on the network. Db2 LUW will allow part of these credentials to be not properly secured in certain situations. Due to this, we need to convert all of our connections to be SSL connections. But in ...
13 days ago in Db2 / Security 0 Submitted

Restrict access of non system data by instance owner

We manage many database systems however as a service provider we do not want the ability to access customer data unless a customer enables this access to us. This should be set at the time of database creation and should not be something that can ...
5 months ago in Db2 / Security 0 Future consideration

schema-privilege for USAGE ON SEQUENCE

To GRANT USAGE ON SEQUENCE there is only the old method with db2 grant usage on sequence sq_test to role <rolename>But i want to use schema-privileges, but there is not the function GRANT USAGEIN ON SCHEMA MYSCHEMA TO ROLE <rolename>; ...
6 months ago in Db2 / Security 0 Future consideration

Revoke on function blocked by depended objects.

The revoke on a function is being blocked due to dependent on the target object. revoke EXECUTE ON FUNCTION "xyz"."aaaaaa"(DATE) from PUBLIC SQL0478N The statement failed because one or more dependencies exist on thetarget object. Target object ty...
9 months ago in Db2 / Security 0 Future consideration

DB2 Certificate Authentication with HSM Support

DB2 certificate authenticated TLS/JDBC connections should be configurable at the client via the standard "DriverManager.getConnection()" mechanism, where parameters are added to indicate that TLS client certificate authentication will be used. It ...
9 months ago in Db2 / Security 0 Future consideration

Update SYSMON_GROUP Authority to include privileges needed for db2top (and other monitoring type functions)

Revisit db2top and dcmtop access requirements to identify the basic monitoring features which require privileges above and beyond sysmon_group privileges and update Db2 to have the sysmon_group given all necessary permissions
11 months ago in Db2 / Security 1 Future consideration

Checksum values for DB2 Install files in Fix Central and Passport Advantages sites

Vendor supplied checksum values are required to validate the authenticity of the binaries downloaded from the vendor sites.As of now, we do have checksum values for few of the Web, Java components and we do need similar features for DB2 binaries a...
about 1 year ago in Db2 / Security 0 Future consideration

Add debugging/information options for encrypted client connections

While configuring/troubleshooting a Db2 LUW server in a setup with encrypted connections, we need methods to identify the encryption status and ciphers used.E.g. Db2 client is connecting to a Db2 LUW server: I have no means to verify, which TLS ci...
over 1 year ago in Db2 / Security 1 Future consideration

Provide the option to exclude SELECT statements from db2audit when collecting DML data

The painful and expensive IBM recommended workaround that ended up not being feasible was to create event monitors (multiple so that records can be cleared) with WLM. However, the volume and format of output generated by the event monitors is diss...
over 1 year ago in Db2 / Security 0 Future consideration

DB2 RCAC Masking usage enhancement

This is urgent request to enhance RCAC masking rule. We are using it on several systems but due to below limitation or bug we have to use static hardcoded values in the masking rule, which is lot of manual process and impose security risk.This fea...
over 1 year ago in Db2 / Security 0 Future consideration