Skip to Main Content
IBM Z Hardware and Operating Systems Ideas Portal


This is the public portal for all IBM Z Hardware and Operating System related offerings. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

ADD A NEW IDEA

My ideas: RACF

Showing 229 of 3555

Allow Auditing by RACF Group

Allow auditing by RACF group. I need to audit accesses made by a specific RACF group.
almost 9 years ago in z/OS / RACF 2 Not under consideration

Add RACF GLOBAL Support to FASTAUTH Checks

Add RACF GLOBAL Support to FASTAUTH Checks Currently this is not supported as outlined in https://www.ibm.com/support/knowledgecenter/en/SSLTBW_2.3.0/com.ibm.zos.v2r3.icha700/spfgac.htm, but would lead to expanded use of GLOBAL entries to standard...
over 6 years ago in z/OS / RACF 4 Not under consideration

Allow RRSF to distinguish between ALU commands and only propagate RESUMES/PWs commands.

Allow RRSF to distinguish between ALU commands and only propagate RESUMES/PWs commands. Restrict/qualify the type of commands that can be sent across environment instead of existing all or nothing approach.
about 5 years ago in z/OS / RACF 3 Not under consideration

RACF ability for NO-Special-users to remove MFA from user.

We need to implement emergency procedure for MFA-users to allow access without MFA. If somebody get a call in the middle of the night, and drop the phone in the toilet before loging in … we have a serious problem. We have no Security Officers on c...
over 2 years ago in z/OS / RACF 1 Not under consideration

Allow greater flexibility in Certificate Name Filters

The Certificate Name Filters available under RACF today are very rigid in their matching process. As a short-hand, essentially one can consider the name filter as an exact search string match that the certificate subject must contain exactly. This...
almost 4 years ago in z/OS / RACF 2 Not under consideration

Increase the RRSF data size limit

RRSF propagation of NVASAPDT ressources failed Try to activate the AUTOMATIC DIRECTION OF APPLICATION UPDATES in our sysplex environment, but the update for Netview Access are not sent to the other rrsf nodes. The error message is : Application up...
almost 8 years ago in z/OS / RACF 1 Not under consideration

group-SPECIAL should be sufficient to reset a password for a user with the NOEXPIRED keyword even if they the ROAUDIT attribute

group-SPECIAL should be sufficient to reset a password for a user with the NOEXPIRED keyword even if they the ROAUDIT attribute.
over 2 years ago in z/OS / RACF 1 Not under consideration

z/OS Contents Supervision - Request for API's/Exit Points for RACF PROGRAM Class Verification Checks

As z/OS Contents Supervision does not issue standard RACF/SAF interfaces to check profiles in the RACF PROGRAM class when loading programs/modules into storage, the IBM zSecure Admin Access Monitor does not get sight of the authorisation check as ...
over 6 years ago in z/OS / RACF 4 Not under consideration

RACF R_ticketserv callable service should allow PTKTDATA profiles qualified with group and/or userid

Currently the PTKTDATA profile provided to R_ticketserv is limited to a 1-8 characters application name. Extending this to allow profile names of the form application.group.user would allow more granularity to control who can use passickets for a ...
over 1 year ago in z/OS / RACF 2 Not under consideration

Allow LU, LISTGRP, LISTDSD and RLIST-commands on behalf of the owner of a component

Implementation of profiles like:- IRR.LISTGRP.OWNER.owninggroup- IRR.LISTDSD.OWNER.owninggroup- IRR.RLIST.OWNER.owninggroup Userids granted to a profile IRR.LISTDSD.OWNER.$OAB should be able, to list all dataset-profiles with Owner $OAB.This shoul...
over 6 years ago in z/OS / RACF 4 Not under consideration