Skip to Main Content
Integration


This is an IBM Automation portal for Integration products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.


Status Planned for future release
Workspace DataPower Gateway
Created by Guest
Created on Aug 27, 2024

Request to Disable Deprecated SSH Host Key Algorithms (ssh-rsa and ssh-dss) in Datapower next release

We request IBM to provide a feature in future Datapower releases that allows administrators to disable the use of deprecated SSH host key algorithms such as ssh-rsa and ssh-dss. These algoritms have know vulnerabilities, and continued use can expose systems to security risks. Modern cryptographic standards recommend using stronger key algorithms for SSH key exchanges.

Currently there is no option available to turn off the use of ssh-rsa and ssh-dss host key algoritms in Datapower, and the inability to do so is resulting in security vulnerability reports in our environment. As a result, we are seeking the ability to configure SSH settings to comply with current security best practices and standards.

Idea priority Urgent
  • Guest
    Reply
    |
    Sep 3, 2024

    I agree with this RFE, this is a required configuration.

  • Guest
    Reply
    |
    Aug 27, 2024

    I agree with this RFE - the option for which ciphers to use is available for other DataPower service functions, but not SSH.  This should be a configurable setting.

  • Guest
    Reply
    |
    Aug 27, 2024

    I completely agree that the ciphers should not be baked into the firmware  rather admins be allowed select the ciphers needed similar to how we select Ciphers at TLS Client and Server Profiles.

    Although higher versions of DataPower firmware widen the support for strong ciphers, the presence of old and weak ciphers (sha based) flags DataPower servers as Vulnerable in our internal security scans. This is a MUST feature that IBM should prioritize.