LDAP-based authentication

Db2 supports LDAP-based authentication and group lookup functionality via two methods:

  • The LDAP security plug-in module
  • Transparent LDAP

The LDAP security plug-in module allows Db2 to authenticate users defined in an LDAP directory, eliminating the requirement that users and groups be defined locally on the operating system.

When you use LDAP security plug-in modules for authentication, all users associated with the database must be defined on the LDAP server. This includes both the Db2 instance owner ID as well as the fenced user. Commonly, these users are defined in the operating system, but when you use the LDAP security plug-in, these users must also be defined in the LDAP server. In addition, if you use the ...

Get IBM Db2 11.1 Certification Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.