Skip to Main Content
IBM Sterling

This portal is to open public enhancement requests for IBM Sterling products and services. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (

Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.

Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal ( - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal ( - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM. - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Future consideration
Categories Security
Created by Guest
Created on Nov 15, 2022

Internal system required certificates prevention

We received the alert for expired certificate in email. We mistakenly removed the expired document encryption cert doccrypto2. After we worked with the support and we found out this cert is required and even it is expired.

Our problem is if this is a critical certificate, why the system didn't prevent us to delete or some warning for this certificates. Also Sterling have many expired certificate similar like this one and required to use on system.

We believe we are not the only one we deleted the system expired certs. If IBM development team can do something to warn or prevent the action of the certs. This will help a lot of Sterling users.

What is your industry? Government
How will this idea be used?
  1. If the cert is required, they can gray out the delete/edit/checkout of the unique system cert.

  2. If this is important cert for the Sterling system, they should have some warning. e.g. "Caution! This is system cert and make sure you know you are deleting."

  3. Optional, normally before we delete, we always checkout the cert. if the cert contain public and private key, when check out, they should allow to export the full public and private key. Like a checkbox to include the private key and then ask you the security passphrase.

4. Optional, if the cert contain public and private, the Sterling UI should have something show this is public/private cert. In current UI, there are no way to tell if the cert is public only or Public/Private cert.