Release Date: July 2026
Release Type: Feature Release
Branch: 3.3.0
OneDB v3.3.0 introduces secure backend TLS connectivity for IBM Db2 and a new Certificate Profile framework for managing trusted database server certificates.
This release also enhances the Db2 Database Browser with metadata refresh, estimated record counts, object-size information, and clearer handling of unavailable database statistics.
Highlights
Db2 Backend TLS Support
OneDB now supports TLS-encrypted JDBC connections from the OneDB application to an IBM Db2 database server.
When Secure Connection is enabled, OneDB uses the IBM Data Server Driver for JDBC and SQLJ to establish a secure connection to the configured Db2 TLS endpoint.
Db2 backend TLS support includes:
- Encrypted JDBC connections between OneDB and Db2.
- Persisted Certificate Profile selection.
- Optional hostname or IP address certificate validation.
- Db2 JDBC BASIC hostname verification mode.
- Authenticated connection validation over TLS.
- Secure metadata discovery and Database Browser operations.
- Sanitized handling of TLS and certificate-related errors.
OneDB provides user-friendly error messages for common conditions such as:
- Untrusted server certificates.
- Hostname or IP address mismatch.
- TLS handshake failures.
- Unsupported TLS protocols or cipher suites.
- Incorrect Db2 TLS port configuration.
- Missing or unhealthy Certificate Profile artifacts.
Sensitive information such as passwords, internal file paths, certificate contents, and credential-bearing JDBC URLs is excluded from user-facing errors.
Certificate Profile Management
OneDB v3.3.0 introduces Certificate Profiles for managing certificates trusted by database Connections.
The initial database-specific integration is available for Db2 backend TLS connections.
Administrators can:
- Fetch a certificate directly from a database server.
- Upload PEM, CRT, or CER certificate files.
- Review certificate information before trusting it.
- Explicitly confirm certificate trust and import.
- Reuse a Certificate Profile across multiple Connections.
- Repair a Certificate Profile whose managed artifacts are missing or corrupt.
- Replace a certificate when an endpoint presents a different certificate.
- Enable hostname or IP address validation where required.
- Review Certificate Profile health through the Diagnostic Bundle.
A Certificate Profile is uniquely associated with:
- Database type.
- Normalized server host.
- TLS port.
The database name and Certificate Profile name are not part of the endpoint identity. Multiple Connections using the same database type, host, and TLS port may therefore share one Certificate Profile.
Certificate Profiles that are referenced by Connections cannot be deleted.
Certificate Trust Workflow
To configure a secure Db2 Connection:
- Open Connection Add or Connection Edit.
- Configure the Db2 host, port, database, and authentication information.
- Enable Secure Connection.
- Fetch the certificate from the server or upload a PEM, CRT, or CER file.
- Review the certificate details, including:
- Subject
- Issuer
- Validity period
- SHA-256 fingerprint
- Subject Alternative Names
- Select Trust & Import.
- Select or reuse the persisted Certificate Profile.
- Enable hostname verification where required.
- Run Test Connection.
- Save the Connection.
When a Certificate Profile already exists for the endpoint, OneDB presents the appropriate action:
- Use Existing Profile when the existing certificate and managed artifacts are healthy.
- Repair Existing Profile when the managed certificate or trust store is missing, corrupt, or unhealthy.
- Replace Existing Certificate when the endpoint presents a different certificate.
Certificate replacement requires explicit confirmation and displays the current and proposed certificate fingerprints and validity information.
If replacement fails, OneDB preserves the previous usable certificate and trust store.
Certificate Review and Security
Certificates fetched from a server or uploaded by an administrator are not trusted automatically.
OneDB presents the certificate for review before import. The preview and import processes use the same staged certificate data to ensure that the certificate being trusted is the same certificate that was reviewed.
Staged certificate previews are:
- Associated with the authenticated session.
- Short-lived.
- Single-use after successful processing.
- Unavailable to Test Connection until they have been trusted and persisted.
Test Connection accepts only an active persisted Certificate Profile. It does not establish trust using an unconfirmed staged certificate.
OneDB stores Certificate Profile artifacts using secure, managed storage with generated identifiers and restrictive file permissions where supported.
Original uploaded filenames are retained only as descriptive metadata and are not used as managed storage filenames.
Each Certificate Profile uses its own managed PKCS12 trust store. OneDB does not modify the global Java cacerts trust store or use temporary production storage.
Connection Interface Improvements
The Connection Add and Connection Edit pages now organize configuration into the following tabs:
- General
- Security & Advanced
The updated interface separates standard database connection settings from TLS, certificate, and advanced security configuration.
Certificate Profile Diagnostics
Certificate Profile operational errors now include a Reference ID.
The Reference ID can be used by administrators and support personnel to correlate an error across:
- The OneDB user interface.
- Application logs.
- Audit records.
- Diagnostic Bundles.
Diagnostic Bundles now include:
- Sanitized Certificate Profile health summaries.
- Certificate Profile operational event summaries.
- Relevant current and rotated application logs.
- Db2 SQLState and vendor error codes when available.
- Health states for missing or corrupt certificate and trust-store artifacts.
Diagnostic Bundles do not include:
- Raw PEM certificate files.
- PKCS12 trust stores.
- Private keys.
- Passwords.
- Staging tokens.
- Session tokens.
- Credential-bearing JDBC URLs.
Certificate Profile Backup and Restore
OneDB Backup and Restore now includes:
- Certificate Profile database records.
- Connection-to-profile references.
- Managed certificate artifacts.
- Managed PKCS12 trust stores.
- Required protected metadata.
Backup data is handled together with the related OneDB configuration to preserve Certificate Profile references and managed trust material.
Cross-version restore compatibility should be validated before restoring a backup into a different OneDB version.
Db2 Database Browser Enhancements
OneDB v3.3.0 expands the Db2 Database Browser with additional metadata capabilities.
Metadata Refresh
Administrators can refresh Db2 metadata from the Database Browser to retrieve updated schema and database-object information.
Estimated Record Counts and Object Sizes
OneDB now retrieves estimated record counts and object sizes from Db2 catalog statistics where available.
This information helps administrators understand the approximate size and content of Db2 tables without running a full record count query.
Unavailable Statistics
Db2 may report catalog statistics as unavailable when statistics have not yet been collected.
OneDB now displays unavailable values as:
N/A
This prevents missing statistics from being shown incorrectly as zero.
For Db2 views, OneDB does not fabricate estimated record counts or physical object sizes when those values are not available.
Db2 Development and Validation
A parameterized Db2 Docker development environment has been added to support repeatable local integration testing.
The environment supports:
- Plaintext mode.
- Plaintext and TLS mode.
- TLS-only mode.
- Persistent Db2 keystore storage.
- Reusable TLS development certificates.
Automated tests cover:
- Db2 JDBC URL generation.
- Secure Connection configuration.
- TLS certificate trust.
- Hostname and IP address validation.
- Sanitized TLS error handling.
- Authenticated TLS connections.
- Metadata discovery.
- Field Settings.
- Group Field Access.
- Database Browser access.
- Pagination and filtering.
- Masking and tokenization.
- Restricted-user metadata visibility.
Current Db2 Support
OneDB v3.3.0 supports the following Db2 capabilities:
- Authenticated JDBC database connections.
- Plaintext JDBC connections.
- TLS-encrypted backend JDBC connections.
- Persisted Certificate Profile selection.
- Shared Certificate Profiles for matching database endpoints.
- Managed PKCS12 trust stores.
- Optional hostname or IP address certificate validation.
- Schema, table, view, and column discovery.
- Permission-aware metadata visibility.
- Field Settings configuration.
- Group permissions and Field Access.
- Read-only Database Browser access.
- Metadata refresh.
- Estimated record counts and object sizes.
- Pagination and filtering.
- Masking and tokenization in the Database Browser.
- Safe handling of commonly used Db2 data types.
- Server-side validation of inaccessible, invalid, or manually constructed object requests.
Capabilities Not Included
The following Db2 capabilities are not included in OneDB v3.3.0:
- Db2 Listener and DRDA protocol processing.
- Db2 client traffic interception.
- Db2 protocol-level Query Audit capture.
- Db2 protocol-level Query Whitelist enforcement.
- Db2 wire-protocol result-set masking.
- Db2 Migration.
- Db2 frontend TLS support.
- Db2 Database Browser export.
Known Limitations
- The Connection host field currently accepts IPv4 addresses only. DNS hostname validation is therefore not available through the current user interface.
- Certificate Profile integration is initially available for Db2 backend TLS. Oracle, PostgreSQL, MySQL, Microsoft SQL Server, and MongoDB continue to use their existing TLS behavior until Certificate Profile integration is added for those database types.
- A fetched or uploaded certificate must be explicitly trusted and imported before it can be used by Test Connection.
- Global Java
cacertsis not modified. - Tables and views without primary keys may not have deterministic ordering across paginated Database Browser requests.
- Db2 CLOB values are limited by the existing Database Browser maximum cell-display length.
- Db2 BLOB and binary values are represented using safe size markers and are not displayed as raw content.
- Db2 metadata visibility requires an additional read-access validation because the IBM JDBC driver may return metadata for objects that the connected user cannot query.
- Db2 Listener and DRDA protocol processing remain outside the scope of this release.