Skip to Main Content
IBM Z Hardware and Operating Systems Ideas Portal


This is the public portal for all IBM Z Hardware and Operating System related offerings. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Future consideration
Workspace z/OS
Created by Guest
Created on Sep 6, 2023

IPSEC enablement for OSPFv2 with IPv4 to allow for stronger authentication required by the US Government.

Currently, the OSPF Neighbor peering for our US Government contracts leverage MD5 today.  We have an open audit finding stating ---> Since MD5 is vulnerable to 'birthday' attacks and may be compromised, routing protocol authentication must use FIPS 140-2 validated algorithms and modules to encrypt the authentication key. <---- All US Government contract vendors have or will soon have this audit finding.

In discussing with IBM developer Mike Fox, our current option would be to migrate to IPv6 and use IPSEC.  This is a 'heavy lift' and neither the mainframe team nor the network team are in a position to perform this task in a timely fashion.  It was suggested that we open this 'Idea' and have this evaluated for relevancy. 

Ideally, it would benefit 'us' (ALL vendors servicing the US Government contracts) as we are not in a position to deploy IPv6 quickly or in the near future but need to comply with the current audit finding and requirements.

We believe securing the OSPF neighbor links with IPSEC should work for IPv4 in the same way as it does for IPv6.

We understand that there are reports of users who have cobbled together configurations to allow IPSEC to work at securing OSPF neighbor links.  However, this non-recommended/non-supported configuration is not a road we are willing to traverse.

Thanks for the consideration and feel free to reach out with any questions you might have.

Mike

Idea priority Urgent
  • Guest
    Reply
    |
    Sep 15, 2023
    We understand the need to address this, but we will not do it via IPSec, but instead by strengthening the OSPF authentication. Do you agree that will address the need?
    1 reply