Skip to Main Content
Cloud Management and AIOps


This is an IBM Automation portal for Cloud Management, Technology Cost Management, Network Automation and AIOps products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).

Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.

Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Submitted
Created by Guest
Created on Feb 25, 2026

Enhance IWS UNIX/Linux Installer to Support Domain IDs Without Strict POSIX Group Dependency

Enable the IWS UNIX/Linux installer to support Domain IDs in LDAP/SSSD environments without failing due to POSIX group resolution issues by reducing strict dependency on OS-level group mapping or providing configurable group handling.

Why is this useful?

In many enterprise environments, UNIX/Linux systems are integrated with Active Directory using LDAP and SSSD for centralized authentication. Domain IDs are preferred over local accounts for security, compliance, and audit purposes.

Currently, when installing IWS using a Domain ID, the installer fails if the associated POSIX group is not properly resolved, even when LDAP and SSSD are correctly configured. This forces teams to use local IDs, which goes against standard security and governance practices.

Enhancing the installer to handle such scenarios will reduce installation failures, minimize dependency on local accounts, and improve adoption in enterprise environments.

Who would benefit from it?

  • Organizations using Active Directory with LDAP/SSSD integration on UNIX/Linux
  • Enterprises that enforce centralized identity management
  • System administrators managing IWS installations
  • Security and compliance teams that discourage the use of local accounts
  • IBM customers deploying IWS in hybrid or large-scale environments

How should it work?

The IWS installer should be enhanced to:

  • Validate the domain ID and group mappings before starting the installation
  • Provide clear pre-installation checks and error messages for missing POSIX groups
  • Allow administrators to configure or override the group used during installation
  • Support fallback mechanisms when default domain group resolution fails
  • Optionally allow installation using Domain IDs without strict dependency on local POSIX groups, where technically feasible

This improvement would make the installation process more robust, flexible, and aligned with modern enterprise authentication standards.

Business Impact

  • Reduces installation and deployment delays
  • Lowers operational overhead caused by repeated failures and rework
  • Improves compliance with enterprise security standards
  • Enhances customer confidence in IWS deployments
  • Increases product adoption in enterprise environments

Technical Justification

The current installer depends heavily on OS-level group resolution and assumes the presence of locally resolvable POSIX groups. In modern environments using AD, LDAP, and SSSD, group mapping is managed centrally and may not always align with local UNIX expectations.

By introducing better validation, configurability, and flexibility in group handling, the installer can become more compatible with domain-integrated environments without requiring changes to customer infrastructure.

Customer Use Case

An organization uses centralized Active Directory authentication with LDAP and SSSD on UNIX/Linux servers. Local user accounts are restricted by policy. When attempting to install IWS using a Domain ID, the installation fails due to unresolved POSIX groups, even though authentication works correctly.

As a workaround, administrators are forced to create and use local IDs, which violates internal security standards. With the proposed enhancement, the organization would be able to complete the installation using authorized domain IDs without modifying their identity infrastructure.

Expected Outcome

  • Successful IWS installation using Domain IDs in LDAP/SSSD environments
  • Reduced dependency on local system accounts
  • Fewer installation-related support cases
  • Improved compatibility with enterprise identity systems
  • Better overall customer experience
Idea priority Medium