Cloud Platform

Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Post your ideas

Start by posting ideas and requests to enhance a product or service. Take a look at ideas others have posted and upvote them if they matter to you,

  1. Post an idea

  2. Upvote ideas that matter most to you

  3. Get feedback from the IBM team to refine your idea

Help IBM prioritize your ideas and requests

The IBM team may need your help to refine the ideas so they may ask for more information or feedback. The offering manager team will then decide if they can begin working on your idea. If they can start during the next development cycle, they will put the idea on the priority list. Each team at IBM works on a different schedule, where some ideas can be implemented right away, others may be placed on a different schedule.

Receive a notification on the decision

Some ideas can be implemented at IBM, while others may not fit within the development plans for the product. In either case, the team will let you know as soon as possible. In some cases, we may be able to find alternatives for ideas which cannot be implemented in a reasonable time.

If you encounter any issues accessing the Ideas portals, please send email describing the issue to ideasibm@us.ibm.com for resolution.

For more information about IBM's Ideas program visit ibm.com/ideas.

Status Needs more information
Workspace WebSphere Liberty
Created by Guest
Created on Feb 12, 2021

Liberty zOS SAF delegation switch

In WAS z/OS traditional cells, we are using the paramters: com.ibm.security.SAF.authorization = false and com.ibm.security.SAF.delegation = false.
The developers use the application-bnd.xml files to map J2EE roles to a bind-able referenced role in their applications.

Liberty z/OS uses SAF and EJBROLEs described in the link: https://www.ibm.com/support/knowledgecenter/en/SS7K4U_liberty/com.ibm.websphere.wlp.zseries.doc/ae/twlp_sec_rolebased.html
The developers want to continue use in Liberty z/OS the same definitions that they use in WAS z/OS traditional applications. They want to be able to configure the user and group to
role mapping in the server.xml. (It is possible in Liberty which run in other platforms).
They do not want to use the EJBROLEs definitons in RACF.

Would be possible to have a switch in Liberty z/OS to work like Liberty running in other platforms?

https://www.ibm.com/support/knowledgecenter/en/SS7K4U_liberty/com.ibm.websphere.wlp.zseries.doc/ae/twlp_sec_rolebased.html

Use Case
Extra definitons (EBBROLEs) in RACF are needing to run the applications in Liberty z/OS. The EBJROLE definitions should match with the application roles defined by the developers in their code.
RFE ID 148569
RFE URL
RFE Product WebSphere Application Server
Idea Priority Medium
  • Admin
    Alasdair Nottingham
    May 13, 2021

    Liberty on z/OS only integrates with SAF if the zosSecurity-1.0 feature is enabled. If you do not enable that feature you do not get SAF integration which we believe is the equivalent behaviour to the two quoted settings for WebSphere traditional. Is there something about not enabling zosSecurity-1.0 that doesn't work for your situation?