Skip to Main Content
Cloud Platform


This is an IBM Automation portal for Cloud Platform products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.


ADD A NEW IDEA

WebSphere Liberty

Enable DPoP support on OAuth 2.0 under z/OS Connect Enterprise Edition

We have noticed several types of frauds when using tokens via OAuth 2.0. To address this issue, RFC 9449 was published with the implementation of DPoP (Demonstrating Proof of Possession.) "DPoP is an OAuth security extension for binding tokens to ...
3 months ago in WebSphere Liberty Future consideration

Implementing Transaction Propagation and Atomic EJB Transactions in Liberty

This initiative aims to enable support for transaction propagation and atomic EJB transactions within the Liberty runtime environment. These features are critical for applications currently relying on traditional Java EE behavior, and their absenc...
12 months ago in WebSphere Liberty Future consideration

Administration and application traffic on different ports

For better security, an application server's application traffic can be initiated from the web server in the DMZ, but it should not be possible for administration traffic. For Liberty profile, it is difficult to achieve.
over 10 years ago in WebSphere Liberty Future consideration

Combination of Liberty and Java Versions in Container Images on IBM Container Registry (ICR)

WebSphere Liberty follows the Continuous Single Stream Delivery (SSCD) lifecycle policy. Under this policy, for the most recent two releases whose version numbers end with ".3", ".6", ".9", and ".12", interim fixes (iFixes) for security vulnerabil...
4 days ago in WebSphere Liberty Submitted

SSL Certificate Management for Liberty Profile. Certificate expiry Alerting and Certificate Renewal

WAS Liberty Profile requires SSL expiry monitoring and alerting. SSL Certificates are usually valid for many years, and the expiry dates of certificates are often missed, until the system fails due to expired certificates.
about 10 years ago in WebSphere Liberty Not under consideration

Trusted DB2 for z/OS connection for Liberty Profile

It would be very helpful if WAS Liberty Profile supported DB2 trusted connections and trusted contexts. Right now I am forced to use SyncToOSThread functionality but that causes problems with authorization to write to log files. I am working on a ...
about 12 years ago in WebSphere Liberty Future consideration

[Liberty Server] Two Phase Commit support for WOLA to IMS/CICS

Similar to what happen in WebSPhere Applicaiton server, we ask the introduction on Liberty the two phase commit support, for the WOLA channel outbout call to IMS/CICS.
over 9 years ago in WebSphere Liberty Not under consideration

Add OAuth 2.0 mTLS support to Liberty’s native oauth-2.0 provider, specifically around RFC 8705 behavior

For our IBM OpenPages product, one of our Customers in Brazil is especially escalating the need for OAuth 2.0 mTLS support Here is the internal Slack discussion for your reference: https://ibm-cloudplatform.slack.com/archives/C30NGTBFS/p1770919784...
3 months ago in WebSphere Liberty Future consideration

Restrict which http method can be called

For better security, it should be possible to configure what http methods can be used to access an application. For example, application 1 may only allow http get/put. Application 2 may disallow http options. This applies to both traditional WAS a...
over 10 years ago in WebSphere Liberty Not under consideration

Support for custom URL Resource Providers in WebSphere Liberty Profile

Within our company we use WebSphere Liberty Profile during development since it greatly improves the performance. Unfortunately there is some disconnect between full-blown WebSphere and WebSphere Liberty Profile in the area of configuration. The f...
over 12 years ago in WebSphere Liberty Future consideration