Skip to Main Content
IBM System Storage Ideas Portal


This portal is to open public enhancement requests against IBM System Storage products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Under review
Workspace IBM DS8000
Created by Guest
Created on Apr 24, 2025

Standardize certificate management on DS8 device

The DS8 currently uses two different methods to manage digital certificates:

1.  https server certificate (CSR generated and import of signed cert) 

2. Syslog secure forwarding certificate (import of private key and certificate components generated off-host). This is generally less secure method as it requires the user to manage the private key.

These two processes should be simplified to have the option to share a digital certificate as most enterprises use the same internal CA authority to sign and verify secure connections within their internal network. 

Suggestions:

1. APIs to manage certificates and support for all certificate formats.

2. Ansible modules to perform the same tasks.

3. Use a single keystore on DS8 to load certs into.

4. Allow HMC, https server and syslog configs to point to the same certificates on the keystore. 

This will standardise toe certificate management and usage for all DS8 secure functions and allow a simple automation pipeline to renew certificates without human intervention. For example:

Automation Pipeline (Ansible Playbook):

Task 1. Run weekly Ansible job to check DS8 server cert i.e. with simple openssl connect command to extract cert details. Or if IBM provide API to check cert expiry. Either will work.

Task 2. If cert is expiring within 30 days or less, then trigger API call to generate CSR on DS8.

Task 3. Send CSR to Company CA authority to sign.

Task 4. Import signed certificate to DS8 and configure services to use new certificate.

Task 5. Restart HMC if required.

Task 6. Check new certificate is valid i.e. serial number and expiry date (can be openssl connect command).

Task 7. Revoke old certificate in Company CA.

 

Idea priority High