System privileges

Resources: Systems

Resource type: U

Db2 administrative authorities

ACCESSCTRL

XAPLPRIV value: ACNTLAUTU

Privcode 289 (x'121')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.ACCESSCTRL DSNADM
Db2-subsystem.SYSCTRL Start of change1End of change DSNADM
Db2-subsystem.SYSADM Start of change1End of change DSNADM
Db2-subsystem.SECADM DSNADM

SECADM

XAPLPRIV value: SECAAUTHU

Privcode 284 (x'11C')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.SYSADMStart of change1, 2End of change DSNADM
Db2-subsystem.SECADM DSNADM
Note: Start of change
  1. Bypass if the SEPARATE_SECURITY subsystem parameter value is YES. For more information, see SEPARATE SECURITY field (SEPARATE_SECURITY subsystem parameter).
  2. Use of following security capabilities always requires SECADM authority, regardless of the SEPARATE_SECURITY setting.
End of change

SQLADM

XAPLPRIV value: SQLAAUTHU

Privcode 290 (x'122')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.SQLADM MDSNSM or GDSNSM
Db2-subsystem.SYSDBADM DSNADM
Db2-subsystem.SYSADM DSNADM

SYSADM

XAPLPRIV value: SYSAAUTHU

Privcode 85 (x'55')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.SYSADM DSNADM

SYSCTRL

XAPLPRIV value: SYSCAUTHU

Privcode 224 (x'E0')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM
Note: Having a database privilege on database DSNDB04 is the equivalent of having the privilege on any implicit database.

SYSDBADM

XAPLPRIV value: DB2AAUTHU

Privcode 287 (x'11F')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.SYSDBADM DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM
Note: Db2 turns on bit 7 of the XAPLFLG1 field for a user table that includes user defined data type or user defined function. If this bit is on, the RACF access control module bypasses checking for the SYSCTRL authority.

SYSOPR

XAPLPRIV value: SOSEAUTHU

Privcode 296 (x'128')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.SYSOPR DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM
Db2-subsystem.SECADM DSNADM

Db2 privileges

ALTER BUFFERPOOL

XAPLPRIV value: CHKALTBPU

Privcode 113 (x'71')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.SYSOPR DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

BINDADD

XAPLPRIV value: BINDAAUTU

Privcode 88 (x'58')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.BINDADD MDSNSM or GDSNSM
Db2-subsystem.SYSDBADM DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

BINDAGENT

XAPLPRIV value: BNDAGAUTU

Privcode 227 (x'E3')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.owner.BINDAGENT MDSNSM or GDSNSM
Db2-subsystem.SYSDBADM DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

CANCEL DDF THREAD, START | STOP DDF

XAPLPRIV values: CHKDDFU, CHKDDFU, CHKDDFU

Privcode 21 (x'15'), 21 (x'15'), 21 (x'15')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.SYSOPR DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

START | STOP RLIMIT

XAPLPRIV values: CHKSTARTU, CHKSTOPU

Privcode 12 (x'C'), 13 (x'D')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.SYSOPR DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

CREATEALIAS

XAPLPRIV value: CRTALAUTU

Privcode 15 (x'F')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.CREATEALIAS MDSNSM or GDSNSM
Db2-subsystem.SYSDBADM DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM
Note: DBADM and DBCTRL authorities can be used to allow a user to create aliases. See CREATE ALIAS privilege for more information.
Db2-subsystem.database-name.DBCTRL DSNADM
Db2-subsystem.database-name.DBADM DSNADM

CREATEDBA

XAPLPRIV value: CRTDBAUTU

Privcode 66 (x'42')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.CREATEDBA MDSNSM or GDSNSM
Db2-subsystem.CREATEDBC MDSNSM or GDSNSM
Db2-subsystem.SYSDBADM DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

CREATESG

XAPLPRIV value: CRTSGAUTU

Privcode 67 (x'43')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.CREATESG MDSNSM or GDSNSM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

CREATETMTAB

XAPLPRIV value: CRTTMAUTU

Privcode 248 (x'F8')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.CREATETMTAB MDSNSM or GDSNSM
Db2-subsystem.CREATETAB MDSNDB or GDSNDB
Db2-subsystem.SYSDBADM DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

Create Secure Object

XAPLPRIV value: CRTSOAUTU

Privcode 285 (x'11D')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.CREATESECUREOBJECT MDSNSM or GDSNSM
Db2-subsystem.SYSADM1 DSNADM
Db2-subsystem.SECADM DSNADM

DEBUGSESSION

XAPLPRIV value: DEBUGAUTU

Privcode 282 (x'11A')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.DEBUGSESSION MDSNSM or GDSNSM
Db2-subsystem.DATAACCESS DSNADM
Db2-subsystem.SYSADM DSNADM

Start of changeDISPLAY, DISPLAY BUFFERPOOL, DISPLAY RLIMITEnd of change

XAPLPRIV values: CHKDISPLU, CHKDSPBPU

Privcode 62 (x'3E'), 112 (x'70')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.DISPLAY MDSNSM or GDSNSM
Db2-subsystem.SYSDBADM DSNADM
Db2-subsystem.SYSOPR DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

DISPLAY ARCHIVE

XAPLPRIV value: DARCHAUTU

Privcode 244 (x'F4')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.DISPLAY MDSNSM or GDSNSM
Db2-subsystem.ARCHIVE MDSNSM or GDSNSM
Db2-subsystem.SYSDBADM DSNADM
Db2-subsystem.SYSOPR DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

Start of changeDISPLAY DYNQUERYCAPTURE, DISPLAY PROFILE, DISPLAY MLEnd of change

XAPLPRIV value: CHKDSPLPU, CHKDSPBPU

Privcode 9 (x'9')

The user must have sufficient authority to:

One of these resources: In class:
Start of changeDb2-subsystem.DISPLAYEnd of change Start of changeMDSNSM or GDSNSMEnd of change
Db2-subsystem.SQLADM MDSNSM or GDSNSM
Db2-subsystem.SYSDBADM DSNADM
Db2-subsystem.SYSOPR DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

Explain

XAPLPRIV value: EXPLNAUTU

Privcode 286 (x'11E')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.EXPLAIN MDSNSM or GDSNSM
Db2-subsystem.SQLADM MDSNSM or GDSNSM
Db2-subsystem.SYSDBADM DSNADM
Db2-subsystem.SYSADM DSNADM

MONITOR1

XAPLPRIV value: MON1AUTU

Privcode 16 (x'10')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.MONITOR1 MDSNSM or GDSNSM
Db2-subsystem.MONITOR2 MDSNSM or GDSNSM
Db2-subsystem.SQLADM MDSNSM or GDSNSM
Db2-subsystem.SYSDBADM DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

MONITOR2

XAPLPRIV value: MON2AUTU

Privcode 17 (x'11')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.MONITOR2 MDSNSM or GDSNSM
Db2-subsystem.SQLADM MDSNSM or GDSNSM
Db2-subsystem.SYSDBADM DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

Query Tuning

XAPLPRIV value: QRYTAUTU

Privcode 294 (x'126')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.SQLADM MDSNSM or GDSNSM
Db2-subsystem.SYSDBADM DSNADM
Db2-subsystem.SYSOPR DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

RECOVER BSDS

XAPLPRIV value: CHKBSDSU

Privcode 93 (x'5D')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.BSDS MDSNSM or GDSNSM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

RECOVER INDOUBT

XAPLPRIV value: CHKRECOVU

Privcode 72 (x'48')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.RECOVER MDSNSM or GDSNSM
Db2-subsystem.SYSDBADM DSNADM
Db2-subsystem.SYSOPR DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

SET ARCHIVE

XAPLPRIV value: SARCHAUTU

Privcode 243 (x'F3')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.ARCHIVE MDSNSM or GDSNSM
Db2-subsystem.SYSOPR DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

START PROFILE

XAPLPRIV value: CHKSTRTPU

Privcode 10 (x'A')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.SQLADM MDSNSM or GDSNSM
Db2-subsystem.SYSDBADM DSNADM
Db2-subsystem.SYSOPR DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

STOP PROFILE

XAPLPRIV value: CHKSTOPPU

Privcode 11 (x'B')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.SQLADM MDSNSM or GDSNSM
Db2-subsystem.SYSDBADM DSNADM
Db2-subsystem.SYSOPR DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

STOPALL

XAPLPRIV value: CHKSUBSYU

Privcode 80 (x'50')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.STOPALL MDSNSM or GDSNSM
Db2-subsystem.SYSOPR DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

STOSPACE UTILITY

XAPLPRIV value: STOAUTU

Privcode 107 (x'6B')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.STOSPACE MDSNSM or GDSNSM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM

START | STOP | MODIFY TRACE

XAPLPRIV value: CHKTRACEU

Privcode 84 (x'54')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.TRACE MDSNSM or GDSNSM
Db2-subsystem.SQLADM MDSNSM or GDSNSM
Db2-subsystem.SYSDBADM DSNADM
Db2-subsystem.SYSOPR DSNADM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM
Db2-subsystem.SECADM DSNADM

USE ARCHIVE LOG

XAPLPRIV value: ARCHAUTU

Privcode 231 (x'E7')

The user must have sufficient authority to:

One of these resources: In class:
Db2-subsystem.ARCHIVE MDSNSM or GDSNSM
Db2-subsystem.SYSCTRL DSNADM
Db2-subsystem.SYSADM DSNADM