Skip to Main Content
IBM Z Hardware and Operating Systems Ideas Portal


This is the public portal for all IBM Z Hardware and Operating System related offerings. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Delivered
Created by Guest
Created on Jul 7, 2023

Certificate Management enhancement - Key Size and allow P12 Repository import

This relates to the Certificate Management Task (z15 and DS8K) and also to the TLS configuration in the Card Specific Advianced Funtions on the OSA ICC configuration.

It should be possible to specify the length of the private key used in the certificate signing request (CSR) generation.  It is important that a key lenght >2048 bits can be specified as this length ist no longer really safe.  It should be possible to specify a 3k and 4k key length.  

It should also be possible (or as an alternative to the above idea) to import a P12 repository in the certificate management dialogs.  This  has already been implemented on the DS8K HMC v9.2 where there is the option "Import Repository" in the Advanced menu on the Certificate Management Task. This would allow the customer to have the full flexibility on creating the CSR and loading a consistent set of certificates into the HMC.  It should be possible to load the P12 from an FTP location, local storage device or via the browser from a remote file system.

 

Idea priority Medium
  • Guest
    Reply
    |
    Sep 3, 2024
    Increase key length, but give selection options of 2048, 3072, 4096 for new certificates
    ? New Default: 3072
    ? 3072-bit keys required to conform to EMEA Standards
    ? Enhancement provided in HMC & SE MCL Bundles H26/S34
    ? Bundle H26 available
    ? Bundle S34 available
    ? If H26 fix is active & S34 is not on z16 (or z15 or earlier system is targeted),
    » HMC Certificate will support for longer key length options including SOO (Single Object Operations) to SE/CPC
    » OSA-ICC Certificate will only provide the 2048 key length option, but z16 CPCs (with S34) will get the 2K, 3K, & 4K options.

    Importing keys does not conform to our strategy and is not supported
  • Guest
    Reply
    |
    Apr 24, 2024

    In Germany we have regulations from the goverment that we have to follow. These regulations are described in BSI document "Technische Richtlinie, Kryptographische Verfahren: Empfehlungen und Schlüssellängen" BSI TR-02102-1, Version 2023-01.

  • Guest
    Reply
    |
    Dec 11, 2023
    Increased key size has been added to our plan for future release. This does not include P12 repository import as this does not align with our security strategy.
  • Guest
    Reply
    |
    Oct 6, 2023

    I support this as a strong requirement for our enterprise. For RSA certificates, our security compliance rules require a key length at least 3000.

18 MERGED

Possibility to create CSR files with key length of 4096 bits

Merged
When creating a new CSR file on an IBM Z HMC there is no option to select the key size. The generated certificate request has a fixed key size of 2048. In several countries especially for Germany it is a recommendations of the local authorities th...