Enabling caching of MFA and RACF PassTickets credentials for clients without sysplex workload balancing
You can enable Db2 to store multi-factor authentication (MFA) credentials in the Db2 global authentication cache for distributed clients that do not use sysplex workload balancing or seamleass failover, and specify the amount of time that the entry remains if unused.
Before you begin
- For clients that have sysplex workload balancing or seamless failover enabled, see Enabling caching of MFA-based authentication credentials for clients with sysplex workload balancing.
- The multi-factor authentication support that is provided by Db2 is based on the IBM Z® Multi-Factor Authentication product, which provides enhanced logon security, addresses regulatory and industry requirements, and provides centralized and simplified management. If you are using IBM Z Multi-Factor Authentication, it must already be configured on MVS or across the z/OS® sysplex and must be configured in accordance with how clients will provide user authentication credentials from remote applications.
- If you are using RACF PassTickets:
- The security product that you are using must be online.
- Complete the steps in Enabling Db2 to receive RACF PassTickets.
About this task
Multi-factor authentication (MFA) and RACF PassTickets are two distinct methods of providing additional authentication credentials at logon to verify a user's identity. Requiring an additional authentication credential ensures that a user's account cannot be compromised if one of their credentials is discovered.
Caching of MFA-based authentication credentials eliminates connection authentication failures that occur when clients that are not sysplex-WLB enabled connect to multiple members of a data sharing group on behalf of the original client application connection. Without caching of MFA-based authentication credentials enabled, connection authentication requests will fail because the additional authentication credential expires or becomes void because it's valid only for the initial connection request and cannot be reused for subsequent connection requests.
Procedure
To enable the caching of MFA credentials for clients that are not sysplex-aware, complete the following steps:
What to do next
If Db2 issues message DSN3582I, take the required actions. For more information, see the system programmer response in DSN3582I.