Security & public access

A public front door with a controlled path to IBM i.

PristineScreen400 authenticates each person at the application boundary, resolves only their approved IBM i grants, and keeps host credentials and connection controls on the server.

Plan a security review

Public HTTPS entry

Managed application identity

Private IBM i connectivity

Typed, audited operations

The connection boundary

The browser is never a credential broker.

A browser sends a selected grant identifier. It cannot submit an IBM i profile, password, host, port, TLS option, command string, SQL string, or connector object.

01 · PUBLIC

Authenticated browser

Branded HTTPS access, application sign-in, opaque HttpOnly session, and only the user’s granted IBM i profiles.

02 · POLICY

PristineScreen400 server

Grant resolution, credential decryption, workspace ownership, redaction, typed capabilities, approvals, and activity.

03 · PRIVATE

IBM i services

One server-configured, explicitly allow-listed target reached only over certificate-validated TLS services.

Defense in depth

Controls at every step of the session.

AUTH

Dedicated application identity

Users sign in to PristineScreen400 rather than sharing or repeatedly entering IBM i credentials. Application passwords use salted, versioned PBKDF2-HMAC-SHA256 records.

SECRETS

Server-side IBM i credentials

IBM i passwords use AES-256-GCM with per-record nonces and an external encryption key. Stored values are never redisplayed or returned by browser APIs.

ACCESS

Exact profile grants

An administrator grants an IBM i identity to an application user. Disabling the user or identity, or revoking the grant, closes affected workspaces.

TRANSPORT

Validated TLS

The IBM i target is configured and allow-listed by the operator. Certificate and endpoint identity validation remains mandatory for terminal and management connections.

REDACTION

Protected browser projection

Non-display terminal values are removed before the connector boundary returns a browser-safe screen projection. Password fields never become accessible terminal text.

SESSION

Owned workspaces

Every terminal, tool operation, activity item, and delegated action stays bound to one authenticated owner, selected grant, revision, and current screen sequence.

Supported public ingress

Customer access terminates at the application, not the host.

Public deployments expose the reviewed PristineScreen400 HTTPS entry while IBM i remains on private networking. Each customer deployment is isolated with its own brand, user store, grants, presentation assignments, credential material, and active IBM i target.

  • No browser-selected IBM i target
  • No direct TN5250 or JTOpen exposure
  • No plaintext host connection mode
  • No public MCP endpoint
  • No shared multi-customer target selector
The customer sees their branded application entry. Host credentials stay behind it.

Beyond the terminal

Management access is typed, bounded, and observable.

The IBM i tools panel does not expose JTOpen or a general-purpose system API. A fixed capability catalog defines exact input, result, risk, approval, and resource scope contracts.

1

Server ceiling

The operator decides which compiled capabilities and maximum risk can exist in a deployment.

2

Administrator assignment

Each exact user and IBM i grant receives visible capabilities, approvals, and resource allow-lists.

3

Runtime enforcement

Every invocation rechecks ownership, grant, capability, resource, revision, screen sequence, and approval.

4

Observable outcome

Activity records safe actor, operation state, and outcome without logging credentials or sensitive payloads.

A preset never hides effective permissions. Administrators can inspect every materialized assignment.

Security facts

Designed to fail closed.

Application sessions
Opaque random tokens, hash-only persistence, HttpOnly and SameSite Strict cookies, fixed server-side expiry
Credential encryption
AES-256-GCM, external protected key file, authenticated record context, transactional key rotation
IBM i transport
TLS 1.2 or TLS 1.3, certificate validation, endpoint identity verification, explicit target allow-list
Terminal input
Serialized, screen-sequence-aware, keyboard-lock-aware, bounded printable input and approved terminal keys
Management operations
Closed typed schemas, resource scopes, risk ceilings, approval policy, timeout, idempotency, sanitized outcomes
Customization
Approved text and color tokens, sanitized PNG assets, closed optional screen templates, Classic fallback

Review it with your team

Map PristineScreen400 to your public access and IBM i security requirements.

Plan a security review