Skip to Main Content
IBM Z Hardware and Operating Systems Ideas Portal


This is the public portal for all IBM Z Hardware and Operating System related offerings. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Not under consideration
Workspace z/OS
Categories RACF
Created by Guest
Created on Jul 4, 2025

Set RVARY password encryption as default

I just learned today that you have to explicitly tell RACF you want the RVARY password encrypted with the KDFAES positional, why is this not done by default? Doesn't seem like it would hurt anything to force everyone to use encryption on their database passwords.

It would be nice if we at a minimum could get an option to have all RVARYPW commands use KDFAES by default so that RACF administrators don't forget to do it, but honestly I think it should just be forced.

Idea priority Medium
  • Guest
    Jul 15, 2025
    With the support added in APAR OA65423, the KDFAES keyword only needs to be specified the first time. Subsequent RVARY password changes will use KDFAES by default. Please see the APAR text for more details.