Skip to Main Content
IBM Z Hardware and Operating Systems Ideas Portal


This is the public portal for all IBM Z Hardware and Operating System related offerings. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

ADD A NEW IDEA

Crypto HW

Showing 43

Crypto Hardware Adjunct Processor Assignment

Crypto Adjunct Processors (APs) are assigned to Crypto PCHIDs at Power-on Reset time. In our experience they differ across multiple z15s despite being identical in hardware configuration. Can we manually assign APs to PCHIDs even if it requires a ...
over 4 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 1 Future consideration

No support of TR31 Block D K1 keys with dual mode of use

ICSF does not support TR31 K1 keys of type D with mode of use B(for encrypt and decrypt). CSNBT31I service ends with cc8/rsn7e0 (incorrect rule array parameter content). This makes ICSF CCA incompatible with authorities that do not separate KEKs a...
over 1 year ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 0 Future consideration

The Symmetric Algorithm Decipher callable service does not provide support to handle JWE Compact Serialization and none of the other callable services have support for this functionality.

The Symmetric Algorithm Decipher callable service does not provide support to handle JWE Compact Serialization and none of the other callable services have support for this functionality.
almost 2 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 2 Future consideration

eIDAS for ICSF and MCL for CEX*S

Remote Signatures according eIDAS (eIDAS is an EU regulation on electronic identification and trust services for electronic transactions in the internal market. It is a set of standards for electronic identification and trust services for electron...
over 7 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 6 Not under consideration

Formatting Method PKOAEP2 in callable service CSNDPKE

Implement the PKOAEP2 formatting method (RSA DSI PKCS #1 v2.1 RSAES-OAEP) in the callable service CSNDPKE (PKA Encrypt). Currently PKOAEP2 is available in the callable services CSNDSYX and CSNDSYI2.
over 2 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 2 Planned for future release

simplify repair actions of broken crypto cards

If a crypto card has broken in zHW, it is very complex to bring a replaced card in production again. Two or more people has to be at TKE to do that. Usually, this people are not at standby, so it could last a couple of days to be fully redundant a...
over 2 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 2 Not under consideration

Copy the contents of a crypto card to a new crypto card after a defective card has been replaced

After a replacement of single cryptocard, in case of a broken card, it should be possible to copy the complete config from another active card in the CEC.
over 5 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 2 Not under consideration

Enable the exchange of MDK keys to Visa using TR-31 Key Block Version B, mode of use=N

We are unable to send MDK keys to Visa using TR-31 Key Block Version B as they use Thales payShield HSMs which only support Mode of Use=N whereas IBM only supports Mode of Use=X.
over 2 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 3 Planned for future release

Specify of the slot location for the CryptoExpress

Allow customer specification of the slot location for the Crypto card.Customer requested to specify of the slot location of the CryptoExpress with new AP number. It is also effective for ensuring redundancy.
over 5 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 2 Not under consideration

New verb for time adjustment in crypto card and sync daemon

A new verb for the crypto cards is needed which allows to adjust the internal clock by a max. of 2 seconds per day.This verb needs his own access point.The intention is to keep the internal crypto card clock synchronized with the server time which...
over 8 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 6 Planned for future release