Skip to Main Content
IBM Z Hardware and Operating Systems Ideas Portal


This is the public portal for all IBM Z Hardware and Operating System related offerings. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

ADD A NEW IDEA

RACF

Showing 236

Logon-ability with a Business Role

Definition of a Member-Class, the profiles are the name of the Business-Role, the members are group-names that represent different access-rights.Example:Profile: RACF-SystemadministratorMember:#TSOBASE Group for TSO-Basic-Rights#SDSF001 Group for ...
about 7 years ago in z/OS / RACF 5 Not under consideration

Have RACDCERT ADD support adding from USS files

RACDCERT ADD currently only supports adding a certificate from a dataset with pretty severe restrictions. I quote: You must specify a cataloged data set, and it may not be a PDS or a PDS member. The record format (RECFM) expected by RACDCERT is va...
about 7 years ago in z/OS / RACF 2 Not under consideration

additional information for certificates in keystores

additional information for certificates in keystores (RACF, .kdb, .jks )Data-installation-fieldLast-use-date for certificatesLast-use-date for keyrings and certificates in keyrings plus SMF-records for certificates (also information in logs, cms,…...
almost 9 years ago in z/OS / RACF 3 Not under consideration

Add New Optional parameter to delete a userid with norule.

This rule is useful when someone try to delete a userid(ex- which support the dataset rule), but try to retain the rule( ex-dataset). this is useful if you have a dataset HLQ which is used by CICS region but you dont want to manage a userid as tha...
almost 2 years ago in z/OS / RACF 4 Not under consideration

Add LOC= parameter on RACROUTE EXTRACT macro

The z/OS Security Server RACROUTE EXTRACT macro only support returning a 24bit EXTRACT response area. The response info may exceed the amount of 24bit storage in an MVS address space. We would like support to be added for a LOC=ANY parameter so th...
about 7 years ago in z/OS / RACF 2 Not under consideration

Enhance RACF type 80 Access Records to always record the module name if WHEN(PROGRAM) grants access

In the current type 80, I do not see a field to indicate the name of the module that grants the access if a conditional permit of WHEN(PROGRAM) grants access. Please enhance the type 80 access records to record the module name for success, failure...
about 9 years ago in z/OS / RACF 2 Not under consideration

Enhancement to RACF ListChain

Any chance to enhance LISTCHAIN to format out some messages tellingabout + alternate CA pathes + existence of 'cross certify' intermediate CA certificates + use a well prepared keyring to favour a well prepared CA path Jörg SeitzIBM TSS Networking...
over 7 years ago in z/OS / RACF 1 Not under consideration

Protect RACF Database to prevent inadvertent deletion

System admins have priviledged access to datasets and system resources. While doing cleanup of antiquated database files an administrator inadvertently deleted the live primary and backup RACF databases causing an outage. Can the RACF task be modi...
almost 2 years ago in z/OS / RACF 1 Functionality already exists

Create an attribute that would prevent the REVOKE of a UserID due to incorrect password attempts

Requesting the creation of an attribute that would exist on the User ID that would prevent/override the User ID from being revoked due to invalid password attempts. Any successful authentications should be allowed. Unsuccessful authentications sho...
almost 2 years ago in z/OS / RACF 0 Future consideration

More granular setup of healthcheck RACF_SENSITIVE_RESOURCES

Healthcheck RACF_SENSITIVE_RESOURCES covers a lot of different resources. If one of the checks fails the whole check fails. To prevent false-postive checks on this healthcheck the only option is to deactivate the healthcheck as a whole. It would b...
almost 2 years ago in z/OS / RACF 3 Not under consideration