Skip to Main Content
IBM Z Hardware and Operating Systems Ideas Portal


This is the public portal for all IBM Z Hardware and Operating System related offerings. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

ADD A NEW IDEA

ICSF

Showing 36

Support for 4096-bit Diffie-Hellman Key Size

The maximum size for a Diffie-Hellman key exchange supported is currently 2048 bits. There are many applications using bigger key sizes and z/OS would not be able to communicate with them. This enhancement would allow 4096-bit and higher key sizes...
about 4 years ago in z/OS / ICSF 1 Future consideration

Allow backup/restore of "TOKEN' within TKDS

Need capability to backup/restore objects within an individual TOKEN.... Need to restore objects with original handles. IE sequence numbers have to be same so applications do not have to change code. Restoring TKDS is not an option as each TOKEN i...
over 5 years ago in z/OS / ICSF 1 Future consideration

Populate SMF 82 40 CMACZERO fingerprint for more key types

Having a single key fingerprint or checksum in the SMF data leads to collisions when trying to validate that the same key is not present in multiple environments. Having a second fingerprint in the SMF 82 40 records would help us to determine whet...
over 1 year ago in z/OS / ICSF 2 Future consideration

Availability of Cryptographic Services

When ICSF is started it will check the Master Key Verification Patterns(MKVP) in the header records of the CKDS and PKDS. When an MKVP is found then a check is made to see if that Master Key is found in the coprocessors. If it is found and it matc...
almost 4 years ago in z/OS / ICSF 1 Future consideration

Option to ignore CRL expiry date in TR34 ICSF services

TR34 RKL ICSF services CSNDT34B and CSNDT34D uses CRL from CA for generating the TOKEN. One of the CA is sending a CRL valid for only one day, but confirmed that the EPP does not validate the CRL End date. Is it possible to provide an option to ig...
about 3 years ago in z/OS / ICSF 1 Future consideration

Isolate PCI traffic from non-PCI traffic on the crypto cards

One of our teams has to purchase hardware security module (HSM) to handle the encryption of the PCI traffic. If CSF could separate the PCI from the Non-PCI traffic, this could allow our team to use the hardware encryption process instead of buying...
8 months ago in z/OS / ICSF 3 Functionality already exists

List available SSL/TLS Ciphers with info about use of Crypto Cards

In CICS communication (SSL/TLS) with ATM a Cipher is selected/negotiated. Please make a list of all ciphers with informations about which can run in the CryptoCard e.g. CEX6C (HW) to offload the usage of CPU, and which can only run using the norma...
over 4 years ago in z/OS / ICSF 0 Future consideration

enhance ICSF panel R to list out the ACPs the same way as the TKE workstation.

Hi there, Currently ICSF panel R only alphabetically lists out only the enabled ACPs in just one big list. ICSF manual alphabetically lists out all available ACPs but also in one big list. my RFE is to request for ICSF panel R enhanced to list out...
almost 7 years ago in z/OS / ICSF 0 Future consideration

ICSF: Determine when key was last used for encryption

We would like a way to determine when a key was last referenced for encryption.
about 5 years ago in z/OS / ICSF 0 Future consideration

Add ICSF Flush command

Provide a mechanism to complete any remaining ICSF work in-flight to be executed just prior to lpar shutdown. This would be in lieu of actually stopping ICSF.
almost 3 years ago in z/OS / ICSF 1 Future consideration