You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何强制Linux公网IP托管的DB2用户仅用SSL证书登录,禁用50000端口账号密码登录

Got it, let's walk through how to lock down your DB2 instance so only SSL connections are allowed, and disable plain username/password logins on port 50000. Here's a step-by-step breakdown tailored to your Linux-hosted DB2 instance:

1. Prepare SSL Certificates (if you don't have them already)

If you don't have a trusted CA-signed certificate, you can generate a self-signed one using DB2's built-in GSKit tools. Run these commands as your DB2 instance owner (e.g., db2inst1):

  • Create a key database and stash file (stores the password securely):
    gsk8capicmd_64 -keydb -create -db /home/db2inst1/db2ssl.kdb -pw StrongPass_123! -stash
    
  • Generate a self-signed certificate (replace db2.yourdomain.com with your server's public IP or hostname):
    gsk8capicmd_64 -cert -create -db /home/db2inst1/db2ssl.kdb -pw StrongPass_123! -label db2ssl_cert -dn "CN=db2.yourdomain.com,OU=IT,O=YourCompany,L=City,ST=State,C=US" -size 2048 -expire 365
    
  • Export the public certificate to share with connecting clients:
    gsk8capicmd_64 -cert -extract -db /home/db2inst1/db2ssl.kdb -pw StrongPass_123! -label db2ssl_cert -target /home/db2inst1/db2ssl.crt -format ascii -fips
    
  • Set strict permissions on the key files (DB2 needs exclusive access):
    chown db2inst1:db2iadm1 /home/db2inst1/db2ssl.*
    chmod 600 /home/db2inst1/db2ssl.*
    
2. Configure DB2 to Enable SSL Connections

Next, update your DB2 instance configuration to use the SSL certificate and enforce SSL-only connections:

  • Set core SSL configuration parameters:
    db2 update dbm cfg using SSL_SVR_KEYDB /home/db2inst1/db2ssl.kdb
    db2 update dbm cfg using SSL_SVR_STASH /home/db2inst1/db2ssl.sth
    db2 update dbm cfg using SSL_SVR_LABEL db2ssl_cert
    db2 update dbm cfg using SSL_PORT 50001  # Pick your preferred SSL port
    
  • Force all connections to use SSL:
    db2 update dbm cfg using REQUIRE_SSL YES
    
  • Restart the DB2 instance to apply changes:
    db2stop force
    db2start
    
3. Disable Plain Username/Password Logins on Port 50000

Now we'll lock down the non-SSL port to block unencrypted authentication:

  • Option 1: Disable the non-SSL port entirely (recommended)
    If you don't need port 50000 at all, remove it from DB2's service configuration:

    # Check current non-SSL port setting first
    db2 get dbm cfg | grep SVCENAME
    # Clear the service name to stop listening on port 50000
    db2 update dbm cfg using SVCENAME ""
    
  • Option 2: Keep the port but block plaintext auth
    If you need to keep port 50000 for some reason, enforce encrypted credentials even there:

    db2 update dbm cfg using AUTHENTICATION SERVER_ENCRYPT
    db2 update dbm cfg using ENCRYPT_PASSWORD YES
    
  • Restart the instance again to apply these changes:

    db2stop force
    db2start
    
4. Verify the Configuration

To confirm everything works as expected:

  • Try connecting without SSL (this should fail):

    db2 connect to YOUR_DB_NAME user YOUR_USER using YOUR_PASS host YOUR_PUBLIC_IP port 50000
    

    You should get an error like SQL30081N indicating SSL is required.

  • Connect using SSL (this should succeed):

    # Clients need the exported public certificate to trust the server
    db2 connect to YOUR_DB_NAME user YOUR_USER using YOUR_PASS host YOUR_PUBLIC_IP port 50001 security SSL
    
  • Double-check active configuration settings:

    db2 get dbm cfg | grep -E "(SSL|AUTHENTICATION|REQUIRE_SSL)"
    

Quick reminders:

  • If using a CA-signed certificate, import the CA root cert into your DB2 key database first.
  • Update your Linux firewall to allow traffic on port 50001 and block port 50000 (if disabled).
  • Clients must install your server's public certificate in their truststore to connect via SSL.

内容的提问来源于stack exchange,提问作者HHH

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 09:17:09