Skip to Main Content
IBM Z Software


This portal is to open public enhancement requests against IBM Z Software products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

ADD A NEW IDEA

Enterprise Key Management Foundation

Showing 34

Bulk/batch operations from the user interface

I wih that the UKO user interface had some way to import a set of keys, instead the key by key option that is possible at the moment
29 days ago in Enterprise Key Management Foundation / UKO for z/OS 0 Future consideration

Key lifecycle management for old key versions

This idea is related to EKM-I-70 After a key is rotated, there should be options to manage the lifecycle of the old keys. One option could be to set the old version of the key to inactive, so it can not be used for new encryption anymore

It should be possible to move keys from one vault to another

Once a key is created, it stays in the vault it was created in. But there might be reasons for having to transfer the key from one vault to another, like: moving key from test vault to production vault changed responsibilities for the key, if vaul...

There should be a way to synchronize UKO and ICSF key metadata

This is an additional idea to EKM-I-73 There should also be an option to synchronize key metadata between UKO and ICSF. For example, if the expiry date in ICSF is changed, this should be reflected in UKO to be notified (showing key out of sync) to...
15 days ago in Enterprise Key Management Foundation / UKO for z/OS 0 Submitted

There should be an option to chose propagation of key expiry date to ICSF

Currently, in UKO, the expiry date for the key is always propagated to ICSF - which could lead to unwanted effects once the key is expired and data might not be accessible anymore. There is no option to create non-expiring keys. The propagation to...
15 days ago in Enterprise Key Management Foundation / UKO for z/OS 0 Submitted

Add more filters to Audit log for better insights

Currently, the audit log only allows to filter for a given date range a specific user ID a specific subject: key or key template uuid key label key template number It would be useful to also filter for Action and Subject Type, for example to show ...
15 days ago in Enterprise Key Management Foundation / UKO for z/OS 0 Submitted

Allow z/OS keys to be rotated more frequently

Currently, you can only rotate a z/OS key (KMG keystore) every hour. This should be configurable
15 days ago in Enterprise Key Management Foundation / UKO for z/OS 0 Submitted

After rotation, it should be possible to restore older versions of the key

After key rotation on z/OS, both versions, the old and the new one, are active. The old key can't be modified anymore. If the old key gets deleted by accident, it is currently not possible to restore it because the key sync operation is not availa...
15 days ago in Enterprise Key Management Foundation / UKO for z/OS 0 Future consideration

CATTool should Provide Date of Master Key Changes

As part of the Crypto Card or KDS Db2 tables, The CATTool should provide the date that the MKVP value was first stored in the KDS or the date that the MVKP value was changed in the KDS as a result of reencipher. This support was recently provided ...
5 months ago in Enterprise Key Management Foundation / Other 0 Under review

UKO-Agent should have his own Messages in zOS SYSLOG

We have the need to control and automate messages from the UKO agent. So if something changes in a Key Dataset (e.g. CKDS) with UKO, we need to be able to react from zOS. Actually, the only way to be aware of changes there is to analyse SMF data. ...
3 months ago in Enterprise Key Management Foundation / UKO for z/OS 1 Under review