This is an IBM Automation portal for Digital Business Automation products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).
We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:
Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,
Post an idea.
Get feedback from the IBM team and other customers to refine your idea.
Follow the idea through the IBM Ideas process.
Cloud Pak for Business Automation - including Business Automation Studio and App Designer, Business Automation Insights
Business Automation Workflow (BAW) - including BAW, Business Process Manager, Workstream Services, Business Performance Center, Advanced Case Management
Content Services - FileNet Content Manager
Content Services - Content Manager OnDemand
Content Services - Daeja Virtual Viewer
Content Services - Navigator
Content Services - Content Collector for Email, Sharepoint, Files
Content Services - Content Collector for SAP
Content Services - Enterprise Records
Content Services - Content Manager (CM8)
Datacap
Automation Document Processing
Automation Decision Services (ADS)
Operational Decision Manager
Robotic Process Automation
Robotic Process Automation with Automation Anywhere
Blueworks Live
Business Automation Manager Open Edition
IBM Process Mining
Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.
IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.
ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.
See this idea on ideas.ibm.com
Background
The way OAUTH was delivered in CMIS was...
1. User logs into identify provider and user receives a token
2. User passes that token to CMIS
3. CMIS reaches out to the identity provider and asks if the token is valid
The enhancement my org is seeking is...
1. User logs into identify provider and user receives a token
2. User passes that token to CMIS
3. CMIS calls a JWTS service once every 24 hours OR checks a locally downloaded X.509 Certificate to check if the token is valid
Why is it useful?
This is helpful because it greatly reduces the burden on the identity provider with respect to token validation. In this design the number of calls to identity provider is reduced by half. The verification can be done by the CMIS server rather than by the identity provider.
Who would benefit from it?
Any organization that is hosting their own identity provider and is interested in reducing the burden on their identity provider.
Idea priority | High |
By clicking the "Post Comment" or "Submit Idea" button, you are agreeing to the IBM Ideas Portal Terms of Use.
Do not place IBM confidential, company confidential, or personal information into any field.
This is already possible today via WebSphere configuration.
If using traditional WebSphere, then import the X.509 certificate into WebSphere’s trust store and set the
provider_<id>.signVerifyAlias
as described in the WebSphere OIDC configuration documentation here: https://www.ibm.com/docs/en/was/9.0.5?topic=party-openid-connect-relying-custom-propertiesIf using FNCM containers, then add the X.509 certificate to the deployment and specify it in the trusted_certificate_list property in the CR and specify the trustAliasName property in the WebSphere Liberty OIDC configuration as described here: https://www.ibm.com/docs/en/was-liberty/base?topic=SSEQTP_liberty/com.ibm.websphere.liberty.autogen.nd.doc/ae/rwlp_config_openidConnectClient.htm
In the CR, this property can be specified under:
open_id_connect_providers:
provider_name: <name>
. . .
oidc_ud_param:
- trustAliasName: <alias name in truststore>