Skip to Main Content
IBM Power Ideas Portal


This portal is to open public enhancement requests against IBM Power Systems products, including IBM i. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Not under consideration
Workspace IBM i
Categories IBM i Access Family
Created by Guest
Created on Sep 6, 2021

IBM Access Client Solutions (ACS) - to restrict/not restrict Filter option in Printer Output

Anyway IBM can enhanced the filter option in ACS - Printer Output for administrator to restrict or not to restrict for end user.

This printer output option very useful to user to view/save spool file in pdf.

Sometimes some user will explore the Printer Output option and put *ALL spool file and they can view the entire system spool files which should not whereby higher management level reports (spool file) are in the system.Security wise confidential reports are expose to normal user
(attached print screen)
Hope IBM can enhanced by giving administrator an option to allow/not allow this Filter option to user.


Use Case:

Security wise *ALL spool file can be protected especially private & confidential reports.


Idea priority High
  • Guest
    Reply
    |
    Sep 13, 2021

    We appreciate the additional suggestions. However, there are other RFEs that are asking for additional enhancements for the Printer Output filters that may already include these additional suggestions. If not, please open a separate RFE so that correspondence for each request remains clear and focused. The author of this RFE was not aware of the existing property and we need to understand if the existing property satisfies the original request. Changing the status back to Need More Information. We would like to understand from the author of this RFE if the existing property satisfies the request.

  • Guest
    Reply
    |
    Sep 10, 2021

    The problem is when you have a properties file that all users are using.
    Here com.ibm.iaccess.splf.FilterRestricted=true

    But this also inhibits users with *SPLCTL Special authority to modify the Printer Output filter.
    With green screen wrksplf this is not a problem because *SPLCTL Special authority is respected.

    An improvement for ACS could be that the property could be set to something like
    com.ibm.iaccess.splf.FilterRestricted=*UserProfile

    When the user has *SPLCTL authority there should be no restrictions and the filter could be modified.
    And if they don't have it, then the filter could not be modified.

    This solution also makes it easier to grant special users authority to look at other spool files.

  • Guest
    Reply
    |
    Sep 9, 2021

    Thank you for submitting your Request For Enhancement and for including the PMRID so that we can review the background for your specific request. The best way to prevent users from seeing spool files they should not see is to restrict their authority on the IBM i server. If your users have access to a 5250 display session, they would be able to view the same spool files using the WRKSPLF SELECT(*ALL) command unless you have taken steps to restrict their authority.

    For convenience, we already support a way to prevent the Printer Output filter from being modified. This is documented in the AcsConfig.properties file by setting the property:
    com.ibm.iaccess.splf.FilterRestricted=true

    Does this meet the requirement?

  • Guest
    Reply
    |
    Sep 7, 2021

    A solution could be that it was possible to set restrictions according to the *SPLCTL Special authority on the user profile.
    This is one thing that I am missing.

  • Guest
    Reply
    |
    Sep 6, 2021

    Attachment (Description)