Skip to Main Content
Integration


This is an IBM Automation portal for Integration products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.


Status Future consideration
Created by Guest
Created on Nov 21, 2018

refresh security reconnect

REFRESH SECURITY(*) TYPE(SSL) lacks the option equivalent to endmqm -r
to indicate that clients should start a reconnect sequence when security is refreshed.
In other words, reconnectable MQ clients do not try to reconnect when "refresh security(*) type(ssl)" is executed.
Could you add such an option?

Idea priority Medium
RFE ID 127462
RFE URL
RFE Product IBM MQ
  • Guest
    Reply
    |
    Apr 6, 2022

    I have interest in seeing MESNS-I-155 integrated into MQ. The ability to refresh SSL without affecting many channels would greatly help environments that need to be highly available. This can be the case where external partners need an updated CA chain added to the MQ Keystore to continue encrypting their channels.


    It would be interesting if an expiry mechanism could be integrated into the processes that contain static copies of the MQ Keystore. This could provide a solution where pooled connection processes like amqrmppa are marked "old" during a refresh, and new Receiver channel connections are directed to a new amqrmppa process with a new static copy of the MQ Keystore.

  • Admin
    Mark Taylor
    Reply
    |
    Mar 8, 2022

    This is still something we'd like to do, but it's likely to be a different solution than the 9.2.5 client-side implementation. The need for I-96 might diminish if this is done, but it still has some independent validity so we didn't want to merge the two records completely.

  • Guest
    Reply
    |
    Mar 4, 2022

    Hi Mark,

    The 9.2.5 CD release saw a feature for MQ clients allowing for TLS keystore updates to be picked up by any new TLS connections made by the client. Could this functionality be ported over to the server side as well? That would negate the need for this idea of the -r, because it eliminates the connections dropping out entirely, but at the expense of additional system resources being used (therefore meaning customers will need to weigh up the performance considerations vs the security concerns associated with longer lived certificates).

  • Guest
    Reply
    |
    Dec 8, 2021

    Please ensure any solution does not require changes to the MQ client applications code (such as a new option on MQCONNX) as this is hard or impossible to achieve, especially with vendor supplied packages.

  • Admin
    Mark Taylor
    Reply
    |
    Dec 8, 2021

    Unmerged from 217 as the solutions to each have now diverged. But we still hope to deliver a solution for this independently of 217 in a future version of MQ.

  • Admin
    Mark Taylor
    Reply
    |
    Sep 7, 2021

    This has been merged with MESNS-I-217 (MQCONNX not able to use alternative SCO) as our expectation is that our ideas on how 217 could be implemented conveniently go a long way to meeting the need for this one as it would actually remove in most cases, the need to run the REFRESH command.

26 MERGED

Introduce Graceful restart option for REFRESH SECURITY TYPE(SSL)

Merged
When renewing a certificate, it is necessary to refresh the ssl connecitons with the REFRESH SECURITY TYPE(SSL) command withing the queue manager. This has the affect of ending any active channels using SSL/TLS and them allowing them to restart. T...
over 4 years ago in MQ, MQ Advanced & MQ Appliance 1 Future consideration