Skip to Main Content
IBM Sterling


This portal is to open public enhancement requests for IBM Sterling products and services. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

ADD A NEW IDEA

Pinned ideas

PINNED Present Multiple Host Keys - RSA and ECDSA
As with standard Linux servers today Secure Proxy should be able to present Host Keys (more than one) in both RSA and ECDSA formats depending on what type the vendor incoming connection supports. Vendors are demanding Host Keys that are stronger t...

Sterling Secure Proxy

Showing 34

Ability to Scan Files for Viruses in the DMZ before arrival in Secure Zone

Need a facility to contact a server via ICAP to scan files (similar to how QuickFile) works. This can be achieved by installing SSP perimeter servers on the virus server in its zone and have SSP engines leverage a persistent connection between the...
about 6 years ago in Sterling Secure Proxy / Usability 1 Delivered

SSP should support in integrating with other 3rd party Malware checking products using ICAP

SSP should support in integrating with other 3rd party Malware checking products using ICAP protocol similar to what DataPower supports today.
about 6 years ago in Sterling Secure Proxy / APIs & SDKs 3 Delivered

Add TLS 1.3 Support to Sterling Secure Proxy

No description provided
almost 6 years ago in Sterling Secure Proxy / Security 1 Delivered

Block users from attempting authentication at the Secure Proxy level

We have a Secure Proxy engine that is exposed to the internet. As such we are subjected to a large number of "probing" login attempts from usernames such as "root", "admin", etc. All of our login attempts are passed to a Sterling External Authenti...
about 6 years ago in Sterling Secure Proxy / Administration & Configuration 2 Delivered

Forward client IP for all protocols from sterling secure proxy to sterling file gateway

Currently SSP forward IP for HTTP Protocol to sterling b2b integrator but it doesn't have capability to forward client IP for other protocols to sterling b2b integrator. We have a regulatory requirement to capture IP for all inbound files/transact...
about 4 years ago in Sterling Secure Proxy 12 Delivered

Add SSL Support between Sterling Secure Proxy Configuration Manager / Engine and WebSphere MQ

Security mandates that all the connections need to be secured. WebSphere MQ supports SSL but not SSP CM / SSP Engine, adding this functionality allows meeting the newer security requirements.
over 5 years ago in Sterling Secure Proxy / Security 1 Delivered

Ability to reject user access at proxy before authentication check

We would like the ability to create a proxy filter (blacklist) to block unknown user names that result in failed authentication attempts. Many of these attempts come from both domestic and foreign nations, so IP whitelisting is not useful to restr...
about 6 years ago in Sterling Secure Proxy / Security 2 Delivered

reading Source IP address from HTTP headers through for example X-Forwarded-For

Currently there is a dynamic routing feature to read incoming source IP address and base the routing based on this value. However many organizations dont support having source IP address hitting the SSP engine servers. Usually the incoming IP addr...
over 5 years ago in Sterling Secure Proxy / Usability 2 Delivered

SSP to support 9000+ IPs/range nodes in Inbound Netmaps for all protocols

Currently, we have 9000+ IPs/CIDR ranges to allow the traffic from. We have added 9000+ entries in Netmap nodes but when we try to edit/save/add more nodes manually the SSP CM GUI is hanging/breaks/not responding properly/going to inoperable state...
over 3 years ago in Sterling Secure Proxy / Administration & Configuration 2 Delivered

Maintain FIPS support for SSP HSM

JCE FIPS implementation has changed in the JRE shipped with SSP 6.0.2 to add support for TLSv1.3. Require verification that FIPS mode will continue to be supported after migration from 6.0.1.1
over 2 years ago in Sterling Secure Proxy / Security 0 Delivered