Client sends user ID and password; DB2 (via RACF) authenticates - **CLIENT** — DB2 trusts the client's authentication (dangerous — use only in fully trusted networks) - **SERVER_ENCRYPT** — Like SERVER, but credentials are encrypted in transit - **KERBEROS** — Kerberos ticket-based authentication (r