Skip to Main Content
IBM Z Software


This portal is to open public enhancement requests against IBM Z Software products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Delivered
Workspace z/OS Connect
Created by Guest
Created on Jan 18, 2023

Enhance z/OS Connect to fall back to basic authentication if certificate is for an unauthorized user

Currently it appears that if a program running in CICS does not specify to send a client certificate, CICS is then sending it's certificate to z/OS Connect.  In our case this ID does not have invoke access to the API so the attempt fails at that point.  We would not want to give the ID this certificate is associated with (CICS STC ID) access to z/OS Connect (or the z/OS Connect api) as it seems this would allow someone who should not have access to the api the ability to drive it without either a proper certificate or ID/Password.  So what we would like is if z/OS Connect authenticates a user via a digital certificate but then that ID does not have access to z/OS Connect EJBROLE (or whatever profile makes sense, could also be down to the API invoke level?) , that it would then fall back and allow basic authentication.

Idea priority Low
  • Admin
    Demelza Farrer
    Reply
    |
    Feb 22, 2023

    Once a request has been authenticated, if it fails authorization, it is not possible to authenticate a second time using alternative credentials. The workaround in this instaance is to define two httpEndpoints in the z/OS Connect server, one that has client certificate authentication enabled and one that has only TLS enabled. The API can then be invoked over the second endpoint when basic authentication is required.

  • Guest
    Reply
    |
    Jan 25, 2023

    We also added Idea CICSTS-I-2098 which is asking CICS for an option to not send the default certificate with the hope that z/OS connect will then drop down to the basicauth header. Please note that we must use SSL when sending a basicauth header as the credentials are only base64 encoded.