Skip to Main Content
IBM Z Hardware and Operating Systems Ideas Portal


This is the public portal for all IBM Z Hardware and Operating System related offerings. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

ADD A NEW IDEA

ICSF

Showing 35

Add a specific CSF messages id to monitor the correct/(or not) initialization/start-up) of the CSFTTCP started task

Dear, In order to monitor the start-up of the CSFTTCP adress space with CA-OPSMVS automate and according to our standards we would like to have the possibility that CSFTTCP started task generates to the console specific messageids for the correct(...
about 1 year ago in z/OS / ICSF 0 Future consideration

Intrusion Latch Detection on z/OS

When a crypto express card encounters an intrusion latch detection error, this error may not be externalized to z/OS.
over 2 years ago in z/OS / ICSF 2 Future consideration

ICSF should allocate its DD cards after JES is up when started SUB=MSTR

Please enhance ICSF so that when we start it up SUB=MSTR it will eventually allocate it's DD card post JES starting up. The RACF address space exhibits this behavior today so it stands to reason it should be possible with ICSF.
about 4 years ago in z/OS / ICSF 1 Future consideration

Request new function: z/OS ICSF a CCA Rexx/CSFIQF API to display enabled ACPs via the ISPF ICSF panels for each coprocessor.

RFE -- Request new function: z/OS ICSF a CCA Rexx/CSFIQF API to display enabled ACPs via the ISPF ICSF panels for each Crypto co-processors. Need a method via (CCA Rexx - CSFIQF API ?) that we can use on ICSF, other than displaying & copying t...
about 5 years ago in z/OS / ICSF 3 Future consideration

Ability to pull ACP tracking report using ICSF callable service. Adding report generation to ICSF ACP panel.

2 related requests as part of this RFE: 1. ACP tracking report(Across LPARs) generation/extraction using ICSF callable service, which can then be utilized by a batch job or any online (CICS/IMS) job/screen. 2. Adding report generation capability i...
over 5 years ago in z/OS / ICSF 0 Future consideration

Allow backup/restore of "TOKEN' within TKDS

Need capability to backup/restore objects within an individual TOKEN.... Need to restore objects with original handles. IE sequence numbers have to be same so applications do not have to change code. Restoring TKDS is not an option as each TOKEN i...
almost 5 years ago in z/OS / ICSF 1 Future consideration

ICSF Hardware Support for (EC)DHE Key Exchange & TLS1.3 Handshakes

Even for TLS1.2 and for TLS1.3, (EC)DHE key exchange becomes more and more required. (EC)DHE based Ciphers are currently only minimal supported by Hardware (CPACF/Crypto CoProcessor). Also, TLS1.3 has a much larger footprint in terms of CPU consum...
10 months ago in z/OS / ICSF 1 Future consideration

The access control check for services, keys or cryptoz resources should be postponed until after the security product has initialized.

We've changed our ICSF startup to an 'early startup' by setting system parameters ICSFPROC=ICSF and ICSF=xx. We're now noticing the following messages during startup that weren't there before : CSFM012I NO ACCESS CONTROL AVAILABLE FOR CRYPTOZ RESO...
11 months ago in z/OS / ICSF 1 Future consideration

Support for 4096-bit Diffie-Hellman Key Size

The maximum size for a Diffie-Hellman key exchange supported is currently 2048 bits. There are many applications using bigger key sizes and z/OS would not be able to communicate with them. This enhancement would allow 4096-bit and higher key sizes...
over 3 years ago in z/OS / ICSF 1 Future consideration

enhance ICSF panel R to list out the ACPs the same way as the TKE workstation.

Hi there, Currently ICSF panel R only alphabetically lists out only the enabled ACPs in just one big list. ICSF manual alphabetically lists out all available ACPs but also in one big list. my RFE is to request for ICSF panel R enhanced to list out...
over 6 years ago in z/OS / ICSF 0 Future consideration