Skip to Main Content
IBM Sterling


This portal is to open public enhancement requests for IBM Sterling products and services. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

ADD A NEW IDEA

Clear

Pinned ideas

PINNED Present Multiple Host Keys - RSA and ECDSA
As with standard Linux servers today Secure Proxy should be able to present Host Keys (more than one) in both RSA and ECDSA formats depending on what type the vendor incoming connection supports. Vendors are demanding Host Keys that are stronger t...

Ideas

Showing 80 of 2953

Configure Adapter to blacklist user-ids

Hi Team, IBM Sterling Secure Proxy Configuration Manager must have an option at adapter-level to blacklist user-ids. Expectation: By default the incoming traffic [Protocol: SFTP] does prompt for a password. Business Security admins are increasingl...
almost 2 years ago in Sterling Secure Proxy / Security 2 Functionality already exists

Option to Disable Exporting Private keys from SSPCM

Currently we can export Private keys for SSL certificates and private SSH keys using export API in SSPCM which is a security concern. Having an option to disable exporting private keys will strengthen the application and comply with Banking securi...
11 months ago in Sterling Secure Proxy / Security 1 Planned for future release

Provision of adding of extra annotation to Statefulset/Pods using Helm charts Values file

While setting up IBM External Authentication Server in containerized way currently there is no Standard way of adding Extra Annotations to Statefulset/Pods in IBM SEAS helm charts using Values file Right now to add any extra annotations we need to...

Provision of adding of extra annotation to Statefulset/Pods using Helm charts Values file

While setting up IBM SSP in containerized way currently there is no Standard way of adding Extra Annotations to Statefulset/Pods in IBM Sterling Secure Proxy helm charts using Values file Right now to add any extra annotations we need to make chan...
11 months ago in Sterling Secure Proxy / Security 0 Planned for future release

Oracle Enterprise Linux (OEL) Support

Many enterprises have Oracle Enterprise Linux (OEL) as their standard. It would be ideal to add support for OEL OS, so customers can deploy the product without any if and buts we have today in our support statement. https://www.ibm.com/support/kno...

diffie-hellman-group-exchange-sha256 Moduli min bits

As diffie-hellman-group-exchange-sha256 typically used a minimum of 2048 bits for the key size. However for the stronger security, it's recommended to use 3072 bits or even 4096 in SSP. However, we can't change the min bits of moduli in SSP to ful...
about 1 year ago in Sterling Secure Proxy / Security 1 Planned for future release

expand password length to 100 Characters

Consistency of all IBM products to allign with the RACF maximum Password/Passphrase Lengths,
about 1 year ago in Sterling Secure Proxy / Security 1 Planned for future release

Properly document SEAS

There are many screens in SEAS UI that are not documented at all or fully.
about 2 years ago in Sterling External Authentication Server / Administration & Configuration 1 Future consideration

SSP - Disable TLS1.0

SSLv3 is disabled by default in SSP in the java.security file with the following line of code. We have attempted to add TLS1 to disable TLS1.0 only and we were not successful. Adding TSL1 to the list of algorithms disabled all versions of TLS not ...
almost 8 years ago in Sterling Secure Proxy / Security / Usability 0 Not under consideration

SFG/SI users changing password with SEAS

There is presently no way to for a myfilegateway user to change their password if Sterling External Authenticator is used. Which seems odd because SFG can talk to SEA and validate an SSO token. There needs to be a feature to allow users to change ...
almost 8 years ago in Sterling External Authentication Server / Usability 0 Functionality already exists