This is the public portal for all IBM Z Hardware and Operating System related offerings. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).
We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:
Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,
Post an idea.
Get feedback from the IBM team and other customers to refine your idea.
Follow the idea through the IBM Ideas process.
Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.
IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.
ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.
This relates to the Certificate Management Task (z15 and DS8K) and also to the TLS configuration in the Card Specific Advianced Funtions on the OSA ICC configuration.
It should be possible to specify the length of the private key used in the certificate signing request (CSR) generation. It is important that a key lenght >2048 bits can be specified as this length ist no longer really safe. It should be possible to specify a 3k and 4k key length.
It should also be possible (or as an alternative to the above idea) to import a P12 repository in the certificate management dialogs. This has already been implemented on the DS8K HMC v9.2 where there is the option "Import Repository" in the Advanced menu on the Certificate Management Task. This would allow the customer to have the full flexibility on creating the CSR and loading a consistent set of certificates into the HMC. It should be possible to load the P12 from an FTP location, local storage device or via the browser from a remote file system.
Idea priority | Medium |
By clicking the "Post Comment" or "Submit Idea" button, you are agreeing to the IBM Ideas Portal Terms of Use.
Do not place IBM confidential, company confidential, or personal information into any field.
? New Default: 3072
? 3072-bit keys required to conform to EMEA Standards
? Enhancement provided in HMC & SE MCL Bundles H26/S34
? Bundle H26 available
? Bundle S34 available
? If H26 fix is active & S34 is not on z16 (or z15 or earlier system is targeted),
» HMC Certificate will support for longer key length options including SOO (Single Object Operations) to SE/CPC
» OSA-ICC Certificate will only provide the 2048 key length option, but z16 CPCs (with S34) will get the 2K, 3K, & 4K options.
Importing keys does not conform to our strategy and is not supported
In Germany we have regulations from the goverment that we have to follow. These regulations are described in BSI document "Technische Richtlinie, Kryptographische Verfahren: Empfehlungen und Schlüssellängen" BSI TR-02102-1, Version 2023-01.
I support this as a strong requirement for our enterprise. For RSA certificates, our security compliance rules require a key length at least 3000.