Skip to Main Content
Cloud Management and AIOps


This is an IBM Automation portal for Cloud Management and AIOps products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).

Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.

Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Future consideration
Created by Guest
Created on May 25, 2020

Netcool Omnibus Object Server User Repository-Password enforcement policy

Our customer is using Omnibus object server as user repository. And wants to implement the following password enforcement policies.
1. Password history should be enforced for last 4 passwords not to be permitted.
2. Application should enforce password validity of <=90 days.
3. Application password should support 8 to 255 character length along with other complexity criteria for password.
4. Password accepted by the application shouldn't accept 3 or greater consecutive characters of User ID.
5. Password should be complex enough by enforcing user to enter password containing small, Capital characters, numeric (0-9) and special characters (like !@$#).
6. Application must enforce password change on first login.

Idea priority Medium
RFE ID 142619
RFE URL
RFE Product Jazz for Service Management (JazzSM)
  • Guest
    Reply
    |
    Apr 22, 2021

    Due to processing by IBM, this request was reassigned to have the following updated attributes:
    Brand - Cloud
    Product family - Operations Management
    Product - Jazz for Service Management (JazzSM)
    Component - Administration
    Source - Other

    For recording keeping, the previous attributes were:
    Brand - Cloud
    Product family - Operations Management
    Product - Tivoli Netcool/OMNIbus Objectserver
    Component - Product functionality
    Source -

  • Guest
    Reply
    |
    Apr 22, 2021

    JazzSM team started analyzing Point 6 (which is RFE on JazzSM). Will post status update on May-07-2021.

  • Guest
    Reply
    |
    Apr 22, 2021

    Requirements 1 - 5 of this RFE was delivered as APAR IJ30835 in Netcool/Omnibus 8.1.0 fix pack 25:
    https://www.ibm.com/support/pages/node/6361681

    Documentation:

    - Configuring the ObjectServer for authentication
    https://www.ibm.com/docs/en/netcoolomnibus/8.1?topic=authentication-objectserver)

    - OMNIbus automations (see 'alert_user_to_old_passwords' trigger)
    https://www.ibm.com/docs/en/netcoolomnibus/8.1?topic=automations-standard-tivoli-netcoolomnibus

  • Guest
    Reply
    |
    Jun 26, 2020

    Business Justification:

    Application Protection is a must in today's world, password change policy should enforce the basis rule by which application & data could be protected.

    1) There are few eminent clients of Bharti whose resources have been integrated with Netcool using Object Server repository, Password enforcement for these eminent clients are must.
    2) Without password rules enforcement, application is quite vulnerable and unsafe.
    3) Need to expose Netcool over Internet, which makes it more vulnerable and hence definitely requires password rules enforcement.
    4) As per Bharti Security Information policy(Disclosure), this is fundamental to ensure no exposure of client data when application is accessed over internet.