Skip to Main Content
IBM Power Ideas Portal


This portal is to open public enhancement requests against IBM Power Systems products, including IBM i. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Not under consideration
Workspace IBM i
Categories IBM i Access Family
Created by Guest
Created on May 4, 2022

ACS - a security breach -- no way to log off requiring new credentials to be entered

One of my colleagues recently discovered a security breach i ACS. He was giving a user support in ACS and was the first to log on. The setting regarding passwords in ACS was "use shared credentials" ( roughly translated from our native language ). After finishing he suddently realised that the user could start additional sessions with his credentials thus gaining administrator rights !!! There were no way to log off. He had to restart the PC. The same thing happens for Printer output and probably for other options too.

There should be a way to log off so the credentials should be entered again like the first time you log on.


Idea priority High
  • Guest
    Reply
    |
    May 23, 2022

    A not-well-documented easter egg is to locate your acsbundle.jar file and run the following from command line:

    java -jar acsbundle.jar /plugin=maint /clearpwcaches /killdaemon

    (could be scripted also)

  • Guest
    Reply
    |
    May 9, 2022

    So this only leave me with option 1 that is almost equal to restarting the PC.

    Option 2 and 3 are not possible due to restrictions.


  • Guest
    Reply
    |
    May 4, 2022
    Thank you for submitting your Idea to enhance IBM i Access Client Solutions (ACS). Users do not log in to ACS. They log in to an IBM i partition when making a connection. For convenience, ACS provides a variety of ways to handle credentials when connecting to an IBM i partition. This gives the user options from entering their credentials for each connection or sharing them between connections. These are the options available today on the Connection tab for each System Configuration:
    1. Use shared credentials
    2. Use default user name to prompt once for each system (this is the default)
    3. Prompt for user name and password every time
    4. Use Kerberos authentication; do not prompt

    The option chosen will determine how ACS caches credentials for future connections. The option you choose should be chosen thoughtfully based on how a particular ACS session will be used. In the reported case, you basically had multiple users sharing the same ACS session. There are multiple ways to resolve the issue.
    Option 1: Log the user out of the PC session and log back in. This will reset any saved credentials.
    Option 2: Set all partitions to ???Prompt for user name and password every time".
    Option 3: Select the option from the main GUI Tools->Reset for Maintenance.

    Since the options currently available meet the requirement, the requested idea is being declined.

    IBM Power Systems Development