Db2 supports LDAP-based authentication and group lookup functionality via two methods:
- The LDAP security plug-in module
- Transparent LDAP
The LDAP security plug-in module allows Db2 to authenticate users defined in an LDAP directory, eliminating the requirement that users and groups be defined locally on the operating system.
When you use LDAP security plug-in modules for authentication, all users associated with the database must be defined on the LDAP server. This includes both the Db2 instance owner ID as well as the fenced user. Commonly, these users are defined in the operating system, but when you use the LDAP security plug-in, these users must also be defined in the LDAP server. In addition, if you use the LDAP group plug-in module, any groups required for authorization such as SYSADM_GROUP, SYSMAINT_GROUP, SYSCTRL_GROUP, and SYSMON_GROUP must...