Skip to Main Content
IBM Z Hardware and Operating Systems Ideas Portal


This is the public portal for all IBM Z Hardware and Operating System related offerings. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Submitted
Workspace z/OS
Categories RACF
Created by Guest
Created on Dec 11, 2025

RACF - Support of RSA keysize of 8192bit for RACDCERT with zOS 3.2

With zOS 3.2 ICSF does support the key generation of 8192 bit:

ICSF Panel 5.6.6 (CSFPKY22)
[.....]
Generate a new asymmetric key pair record. Select one key type/size:
RSA key bit length:  ____ (512 - 8192)
[.....]                           

 

But when using RACF RACDCERT command to generate a certificate with the same key size, the command fails:

IRRD125I The key size that was specified or defaulted is not acceptable.  The request is not processed.

 

What the ICSF manual states in Chapter 3 . Application Programming Interfaces and key management (https://www.ibm.com/docs/en/SSLTBW_3.2.0/pdf/csfb500_icsf_overview_hcr77f0.pdf)

Generating RSA keys on a Cryptographic Coprocessor Feature You can use the PKA key generate callable service to generate RSA public and private key pairs within the secure boundary of the cryptographic coprocessor. The modulus for the RSA keys may be up to 8192 bits depending on your system. The RSA private key may be retained and used within the secure boundary of the cryptographic coprocessor. The public key and the key name for the private key are stored in the ICSF public key data set (PKDS), but the value of a retained private key never appears in any form outside the cryptographic coprocessor

 

So this request is to enable/allow RACDCERT to use as well RSA key size of 8192 (as supported by ICSF)

Idea priority Medium