Skip to Main Content
IBM Data and AI Ideas Portal for Customers
Hide about this portal


This portal is to open public enhancement requests against products and services offered by the IBM Data & AI organization. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:


Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,


Post your ideas

Post ideas and requests to enhance a product or service. Take a look at ideas others have posted and upvote them if they matter to you,

  1. Post an idea

  2. Upvote ideas that matter most to you

  3. Get feedback from the IBM team to refine your idea


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

IBM Employees should enter Ideas at https://ideas.ibm.com


Password less authentication or API to update password for CDC engine and Management Console

See this idea on ideas.ibm.com

We need the following enhancements on CDC -


(1) CDC engine for IBM iseries needs to support password less authentication like kerberos, or have an API that allows password to be updated.



(2) CDC Management console, need to support password less authentication like kerberos to access IBM I and Oracle data stores, or have an API that allows password to be updated.


Needed By Month
  • Admin
    Davendra Paltoo
    Reply
    |
    Apr 14, 2025

    IBM update.

    We document support for Kerberos with Oracle: https://www.ibm.com/docs/en/idr/11.4.0?topic=databases-setting-up-kerberos-authentication . Is the concern that this was not working when you tried to configure it?


    Note the following comments from L3. (In summary password less communication from MC to Oracle Datastores is feasible with current capabilities):

    "

    When kerberos is configured for the engine, then when MC is trying to connect to the db through CDC engine, if only user name is provided (i.e. password field is empty in the datastore), then CDC will only check if the user exists instead of trying to connect to db using user/password stored in MC."


    If customer doesn’t want to provide login info in MC for a datastore that was configured with kerberos, customer just need to enter a valid db user in the MC and leave password field empty.

  • Admin
    Davendra Paltoo
    Reply
    |
    Apr 11, 2025

    IBM Update.

    Regarding this part of the requirement "(1) CDC engine for IBM iseries needs to support password less authentication like kerberos, or have an API that allows password to be updated., we need more details.


    What exactly is needed where it comes to password less access:

    Here is relevant guidance from L3


    "

    While create CDC instance for IBM i we do not provide database credentials as in confguring LUW CDC engines.


    Installation of CDC instance for IBM i is typically done using the QSECOFR user (or any user who has *SECOFR special authorities).


    For configuring and operating CDC, there are 2 types of user profiles to be taken into consideration:


    CDC operational user: Users who run CDC replication processes, typically users who are logged on through the datastore or who start replication processes from the command line/job scheduler. The CDC source jobs are run under the CDC operational user profile. The CDC operational user requires authorities to the replicated source tables, journals and journal receivers. For target tables, no authorities are required for the CDC operational user since all the apply processes are run under the CDC product user.


    CDC owner/product user: By default, the user profile D_MIRROR. The user profile D_MIRROR is automatically created during installation. CDC requires this user profile to supervise replication operations for the CDC apply processes. The D_MIRROR user profile does not need authorities to the replicated source tables, journals or journal receivers. However, all the CDC apply processes are run under the D_MIRROR user profile, hence the need for this profile to have update rights to the target tables.CDC Management console, need to support password less authentication you mean not to provide the IBM i user profile details while configuring the CDC for IBM i datastore."



  • Guest
    Reply
    |
    Mar 18, 2025

    Hi,

    Can we please have an update on the target date for IBM CDC listener supporting kerberos authentication for RHEL 8 ?
    we need to move away from our current setup which is using password based authentication on the listener to connect to Oracle 19 db.

    We had attempted setting up a Kerberos connection for listener IIDR-11.4.0.5-5733-linux-x86.bin on RHEL 8 however it gave a checksum error due to incompatible SHA512. Database checksum is 'SHA512,SHA256'

    following error was encountered in the setup -
    Error:A SQL exception has occurred. The SQL error code is '0'. The SQL state is: HY008. The error message is:

    [CDC][Oracle JDBC Driver]ORA-12656: Cryptographic checksum mismatch

    Thanks,
    Jitendra

  • Admin
    Davendra Paltoo
    Reply
    |
    Aug 14, 2024

    IBM Update.

    Thanks for filing this requirement.

    We think the requirement is valid. We will keep it on our list of requirements that are candidates for prioritization in future roadmap planning.


    ==


    Comments on 2025.4.15 ^

    Note the subsequent comments made after further review/investigation.

    More information is presently being requested regarding (1) CDC engine for IBM iseries needs to support password less authentication like kerberos, or have an API that allows password to be updated.