Skip to Main Content
IBM Data Platform Ideas Portal for Customers


This portal is to open public enhancement requests against products and services offered by the IBM Data Platform organization. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:


Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,


Post your ideas

Post ideas and requests to enhance a product or service. Take a look at ideas others have posted and upvote them if they matter to you,

  1. Post an idea

  2. Upvote ideas that matter most to you

  3. Get feedback from the IBM team to refine your idea


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

IBM Employees should enter Ideas at https://ideas.ibm.com



Status Future consideration
Workspace Db2
Created by Guest
Created on Apr 3, 2026

Support for Mutual TLS (mTLS) Authentication on DB2 LUW Server

Description:
Currently, DB2 for Linux/Unix/Windows (LUW) does not support mutual TLS (mTLS) for connections between DB2 clients and the DB2 LUW server. mTLS is only available for DB2 on z/OS.
This limitation prevents organizations from implementing a fully zero-trust and certificate‑based authentication model for DB2 LUW workloads.

Problem Statement:
In modern security architectures, especially in regulated environments, mutual TLS is becoming a mandatory requirement to ensure strong authentication, certificate pinning, and encrypted, trusted connections end-to-end.
The lack of mTLS support on DB2 LUW forces teams to rely on alternative or less secure authentication mechanisms, or to introduce additional infrastructure components, which increases complexity and operational risk.

Proposed Enhancement:
Add full support for mutual TLS (client certificate authentication) directly between DB2 LUW servers and DB2 clients, including:

  • Client certificate verification by the DB2 LUW server
  • Configurable certificate authorities
  • Support for certificate revocation (CRL/OCSP)
  • Integration with GSKit or other supported security frameworks
  • Backward compatibility with existing TLS-only implementations

Business Justification:
mTLS support would:

  • Strengthen security posture and align with zero‑trust architectures
  • Simplify secure database connectivity
  • Reduce dependency on external proxies or gateways
  • Improve compliance with requirements from auditors and regulators (e.g., PCI‑DSS, ISO 27001, DORA, NIS2)

 

Needed By Yesterday (Let's go already!)
  • Admin
    Siji Daniel
    Apr 8, 2026

    Hello. Thank you for submitting this Idea.
    We discussed this internally - this request will not be delivered within the release currently under development, but the theme is aligned with our multi-year strategy. This is marked for Future Consideration. We will take user feedback for this request through activities such as voting. We will update this request in the future.

4 MERGED

Certificate authentication for DB2 LUW

Merged
In a heterogeneous environment, certificate authentication enables access to numerous services; among other things, it should also be possible for DB2 clients to connect to a DB2 database and to grant the user identified by the certificate the app...
7 months ago in Db2 / Db2 on-premise Future consideration