Skip to Main Content
Integration


This is an IBM Automation portal for Integration products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.


Status Submitted
Created by Guest
Created on Nov 5, 2025

Enable Token-Based Authentication (IDA IDAnyWhere) for IBM MQ Client/Server Connections

Currently, IBM MQ supports SSL certificate-based authentication for client connections. While this method provides robust security, it introduces significant operational overhead for application teams, who must manage, distribute, and frequently renew certificates. As organizations modernize their application architectures and migrate workloads to cloud platforms such as AWS, there is a growing preference for token-based authentication mechanisms, specifically IDA IDAnyWhere (IDA).

Token-based authentication offers several advantages over traditional certificate-based approaches, including simplified credential management, improved scalability, and enhanced support for dynamic, cloud-native environments. Many modern applications, especially those running on cloud platforms, are designed to leverage IDA for authentication rather than SSL certificates. This shift is driven by the need for agility, automation, and reduced administrative burden.

A substantial number of applications that connect directly to mainframe systems are seeking to use IBM MQ on platforms where IDA is supported. However, the lack of token-based authentication support in IBM MQ is a significant barrier to adoption and modernization. Enabling IDA for MQ client/server connections would align IBM MQ with current industry best practices and support ongoing modernization initiatives across the enterprise.

Use Case:

A financial institution is migrating several mission-critical applications from on-premises infrastructure to AWS. These applications require secure, authenticated connections to IBM MQ running on z/OS and distributed platforms. The institution’s security architecture mandates the use of IDA IDAnyWhere for authentication, as it integrates seamlessly with their identity provider and supports dynamic, cloud-native workloads.

Currently, the application teams must manage SSL certificates for each client connection to MQ, which is time-consuming and error-prone. Certificate renewal cycles often lead to service disruptions and increased operational risk. By enabling token-based authentication (IDA), the institution can:

  • Eliminate the need for certificate management and renewal.
  • Automate authentication workflows using their existing identity provider.
  • Improve developer productivity and reduce operational overhead.
  • Accelerate cloud adoption and support hybrid/multi-cloud architectures.
  • Enhance security posture by leveraging modern, standards-based authentication.

 

Request:

We request IBM to enhance IBM MQ to support token-based authentication using IDA IDAnyWhere for client/server connections. This feature should be available across all supported platforms, including z/OS and distributed environments. The implementation should allow applications to authenticate using IDA tokens, in addition to (or as an alternative to) SSL certificates.

This enhancement will:

  • Align IBM MQ with modern authentication standards.
  • Support enterprise modernization and cloud migration initiatives.
  • Reduce operational complexity for application teams.
  • Enable broader adoption of IBM MQ in cloud and hybrid environments.

We believe this feature will deliver significant value to IBM MQ customers and help maintain IBM MQ’s position as a leading enterprise messaging solution.

Idea priority Medium