<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Talking Identity &#124; Nishant Kaushik&#039;s Look at the World of Identity Management</title>
	<atom:link href="http://blog.talkingidentity.com/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.talkingidentity.com</link>
	<description>An Architect&#039;s Quest to make sense of the world of Identity and Access Management</description>
	<lastBuildDate>Tue, 24 Aug 2010 17:16:51 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Upcoming Webcast on Service-Oriented Security</title>
		<link>http://blog.talkingidentity.com/2010/08/upcoming-webcast-on-service-oriented-security.html</link>
		<comments>http://blog.talkingidentity.com/2010/08/upcoming-webcast-on-service-oriented-security.html#comments</comments>
		<pubDate>Tue, 24 Aug 2010 17:16:51 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Application-Centric IdM]]></category>
		<category><![CDATA[Service-Oriented Security]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1014</guid>
		<description><![CDATA[You&#8217;ve seen me blog a whole lot about Service-Oriented Security over the years; now you can also hear me talk about it. I&#8217;ll be doing a live webcast on &#8220;Service-Oriented Security: Blazing a New Trail of Innovation in Application Security&#8221; on Wednesday, August 25th (that&#8217;s tomorrow!) at 11:00 a.m. PT/2:00 p.m. ET . In it, [...]]]></description>
			<content:encoded><![CDATA[<p>You&#8217;ve seen me blog a whole lot about Service-Oriented Security over the years; now you can also hear me talk about it. I&#8217;ll be doing a live webcast on &#8220;<strong>Service-Oriented Security: Blazing a New Trail of Innovation in Application Security</strong>&#8221; on <em>Wednesday, August 25th</em> (that&#8217;s tomorrow!) at <em>11:00 a.m. PT/2:00 p.m. ET<span style="font-family: Arial,Helvetica,sans-serif; font-size: x-small;"> </span></em>. In it, I and my colleague Bharath Shashikumar will talk about how SOS offers a revolutionary architectural approach to efficiently develop security as discrete reusable services &#8211; resulting in faster development lifecycles, better IT agility and dramatically lower integration costs. You can get more information on the webcast <a href="http://bit.ly/9soO21">here</a> and register to attend for free <a href="http://bit.ly/9aXzr8">here</a>.</p>
<p>And if there are any questions you want to ask me, then ask them during the webcast, or send them my way ahead of time via <a href="http://twitter.com/NishantK">twitter</a>.</p>
<address><img class="alignnone" title="Ziff-Davis Enterprise eSeminars" src="http://www.oracle.com/dm/11h1images/eseminars_170.jpg" alt="" width="170" height="60" /></address>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/application-security" rel="tag">Application Security</a>, <a href="http://blog.talkingidentity.com/tag/application-centric-idm" rel="tag">Application-Centric IdM</a>, <a href="http://blog.talkingidentity.com/tag/service-oriented-security" rel="tag">Service-Oriented Security</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DUpcoming%2520Webcast%2520on%2520Service-Oriented%2520Security%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html%26amp%3Btitle%3DUpcoming%2520Webcast%2520on%2520Service-Oriented%2520Security%26amp%3Bbodytext%3DYou%2527ve%2520seen%2520me%2520blog%2520a%2520whole%2520lot%2520about%2520Service-Oriented%2520Security%2520over%2520the%2520years%253B%2520now%2520you%2520can%2520also%2520hear%2520me%2520talk%2520about%2520it.%2520I%2527ll%2520be%2520doing%2520a%2520live%2520webcast%2520on%2520%2522Service-Oriented%2520Security%253A%2520Blazing%2520a%2520New%2520Trail%2520of%2520Innovation%2520in%2520Application%2520Security%2522%2520on%2520Wednesda';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html%26amp%3Bt%3DUpcoming%2520Webcast%2520on%2520Service-Oriented%2520Security';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html%26amp%3Btitle%3DUpcoming%2520Webcast%2520on%2520Service-Oriented%2520Security';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html%26amp%3Btitle%3DUpcoming%2520Webcast%2520on%2520Service-Oriented%2520Security%26amp%3Bannotation%3DYou%2527ve%2520seen%2520me%2520blog%2520a%2520whole%2520lot%2520about%2520Service-Oriented%2520Security%2520over%2520the%2520years%253B%2520now%2520you%2520can%2520also%2520hear%2520me%2520talk%2520about%2520it.%2520I%2527ll%2520be%2520doing%2520a%2520live%2520webcast%2520on%2520%2522Service-Oriented%2520Security%253A%2520Blazing%2520a%2520New%2520Trail%2520of%2520Innovation%2520in%2520Application%2520Security%2522%2520on%2520Wednesda';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html%26amp%3Btitle%3DUpcoming%2520Webcast%2520on%2520Service-Oriented%2520Security%26amp%3Bnotes%3DYou%2527ve%2520seen%2520me%2520blog%2520a%2520whole%2520lot%2520about%2520Service-Oriented%2520Security%2520over%2520the%2520years%253B%2520now%2520you%2520can%2520also%2520hear%2520me%2520talk%2520about%2520it.%2520I%2527ll%2520be%2520doing%2520a%2520live%2520webcast%2520on%2520%2522Service-Oriented%2520Security%253A%2520Blazing%2520a%2520New%2520Trail%2520of%2520Innovation%2520in%2520Application%2520Security%2522%2520on%2520Wednesda';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html%26amp%3Btitle%3DUpcoming%2520Webcast%2520on%2520Service-Oriented%2520Security';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html%26amp%3Bh%3DUpcoming%2520Webcast%2520on%2520Service-Oriented%2520Security';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DUpcoming%2520Webcast%2520on%2520Service-Oriented%2520Security%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html%2520Upcoming%2520Webcast%2520on%2520Service-Oriented%2520Security';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DUpcoming%2520Webcast%2520on%2520Service-Oriented%2520Security%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fupcoming-webcast-on-service-oriented-security.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/08/upcoming-webcast-on-service-oriented-security.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pushing forward on Standards-based Provisioning</title>
		<link>http://blog.talkingidentity.com/2010/08/pushing-forward-on-standards-based-provisioning.html</link>
		<comments>http://blog.talkingidentity.com/2010/08/pushing-forward-on-standards-based-provisioning.html#comments</comments>
		<pubDate>Tue, 24 Aug 2010 15:57:18 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Burton Catalyst Conference]]></category>
		<category><![CDATA[Cat10]]></category>
		<category><![CDATA[Provisioning]]></category>
		<category><![CDATA[SPML]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1011</guid>
		<description><![CDATA[Lest all the recent posts about &#8220;pull&#8221;-based identity make you think that I have completely forgotten about good old &#8220;push&#8221;-based identity provisioning, here is some news on that. As I have discussed here in the past, SPML has been under a cloud in recent years, with low adoption and a litany of issues being documented. [...]]]></description>
			<content:encoded><![CDATA[<p>Lest all the recent posts about &#8220;pull&#8221;-based identity make you think that I have completely forgotten about good old &#8220;push&#8221;-based identity provisioning, here is some news on that. As <a href="http://bit.ly/a6q8AX">I have discussed here</a> in the past, SPML has been under a cloud in recent years, with low adoption and a litany of issues being documented. At the same time, the need for a standards-based approach has never been clearer. So something needs to be done.</p>
<p>This was the topic of discussion at a SIG on <strong>Standards-based Provisioning</strong> organized by Gartner&#8217;s Mark Diodati at the recent Catalyst conference. The meeting was attended by some really smart folks in the community, and engendered a lively discussion on the future of SPML and the direction it should take. Mark has <a href="http://bit.ly/dDlHhI" target="_blank">published a statement</a> on the Gartner blog network that reflects the outcome of the discussion. Given the recent reboot of the <a href="http://bit.ly/dghWhK" target="_blank">Provisioning Services Technical Committee</a> at OASIS, this is an important document for everyone concerned to read.</p>
<p>One of the most important points raised during the meeting was this:</p>
<blockquote><p>In trying to address every possible use case, interoperable provisioning  services leveraging the SPML v2 standard became impractical. Since the  approval, few (if any) conformant implementations exist due to the  complexity of the v2 standard.</p></blockquote>
<p>The path to success in the standards world is based on a focused approach to solving specific use cases. No standard can be all things to all people, and with provisioning in particular, we need to recognize that there are different approaches that solve the challenge in optimal ways for their use cases (my recent assertion regarding IGF as underlying pull-based provisioning is an example). So there need to be an effort to continue refinement of SPML 2.0, making it simpler to implement and based on specific use-cases that are of interest to the community. If you have such use-cases, please consider joining the discussion within the PSTC and submitting them there. There is much that needs to be done.</p>
<p>And a big thank you to Mark for pulling together the SIG. It was an excellent and timely effort, one that I hope proves instrumental in accomplishing it&#8217;s goal.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/burton-catalyst-conference" rel="tag">Burton Catalyst Conference</a>, <a href="http://blog.talkingidentity.com/tag/cat10" rel="tag">Cat10</a>, <a href="http://blog.talkingidentity.com/tag/provisioning" rel="tag">Provisioning</a>, <a href="http://blog.talkingidentity.com/tag/spml" rel="tag">SPML</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DPushing%2520forward%2520on%2520Standards-based%2520Provisioning%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html%26amp%3Btitle%3DPushing%2520forward%2520on%2520Standards-based%2520Provisioning%26amp%3Bbodytext%3DLest%2520all%2520the%2520recent%2520posts%2520about%2520%2522pull%2522-based%2520identity%2520make%2520you%2520think%2520that%2520I%2520have%2520completely%2520forgotten%2520about%2520good%2520old%2520%2522push%2522-based%2520identity%2520provisioning%252C%2520here%2520is%2520some%2520news%2520on%2520that.%2520As%2520I%2520have%2520discussed%2520here%2520in%2520the%2520past%252C%2520SPML%2520has%2520been%2520under%2520a%2520cloud%2520in%2520r';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html%26amp%3Bt%3DPushing%2520forward%2520on%2520Standards-based%2520Provisioning';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html%26amp%3Btitle%3DPushing%2520forward%2520on%2520Standards-based%2520Provisioning';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html%26amp%3Btitle%3DPushing%2520forward%2520on%2520Standards-based%2520Provisioning%26amp%3Bannotation%3DLest%2520all%2520the%2520recent%2520posts%2520about%2520%2522pull%2522-based%2520identity%2520make%2520you%2520think%2520that%2520I%2520have%2520completely%2520forgotten%2520about%2520good%2520old%2520%2522push%2522-based%2520identity%2520provisioning%252C%2520here%2520is%2520some%2520news%2520on%2520that.%2520As%2520I%2520have%2520discussed%2520here%2520in%2520the%2520past%252C%2520SPML%2520has%2520been%2520under%2520a%2520cloud%2520in%2520r';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html%26amp%3Btitle%3DPushing%2520forward%2520on%2520Standards-based%2520Provisioning%26amp%3Bnotes%3DLest%2520all%2520the%2520recent%2520posts%2520about%2520%2522pull%2522-based%2520identity%2520make%2520you%2520think%2520that%2520I%2520have%2520completely%2520forgotten%2520about%2520good%2520old%2520%2522push%2522-based%2520identity%2520provisioning%252C%2520here%2520is%2520some%2520news%2520on%2520that.%2520As%2520I%2520have%2520discussed%2520here%2520in%2520the%2520past%252C%2520SPML%2520has%2520been%2520under%2520a%2520cloud%2520in%2520r';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html%26amp%3Btitle%3DPushing%2520forward%2520on%2520Standards-based%2520Provisioning';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html%26amp%3Bh%3DPushing%2520forward%2520on%2520Standards-based%2520Provisioning';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DPushing%2520forward%2520on%2520Standards-based%2520Provisioning%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html%2520Pushing%2520forward%2520on%2520Standards-based%2520Provisioning';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DPushing%2520forward%2520on%2520Standards-based%2520Provisioning%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpushing-forward-on-standards-based-provisioning.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/08/pushing-forward-on-standards-based-provisioning.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Identity Services should be like Vitamins, not Crack</title>
		<link>http://blog.talkingidentity.com/2010/08/identity-services-should-be-like-vitamins-not-crack.html</link>
		<comments>http://blog.talkingidentity.com/2010/08/identity-services-should-be-like-vitamins-not-crack.html#comments</comments>
		<pubDate>Thu, 12 Aug 2010 20:45:31 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Identity Services]]></category>
		<category><![CDATA[Cloud Identity Model]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[Service-Oriented Security]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1003</guid>
		<description><![CDATA[OK, so it&#8217;s a ridiculous title. But hear me out.
Matt Flynn brought to my attention an article in which Dale Olds talks about the need for hosters (companies that provide the platform on which you deploy your Cloud/SaaS applications) to provide identity services (and as Matt points out, security services in general) as part of [...]]]></description>
			<content:encoded><![CDATA[<p>OK, so it&#8217;s a ridiculous title. But hear me out.</p>
<p>Matt Flynn <a href="http://bit.ly/ab7V0e" target="_blank">brought to my attention</a> an <a href="http://bit.ly/bnVj4C" target="_blank">article in which Dale Olds talks</a> about the need for hosters (companies that provide the platform on which you deploy your Cloud/SaaS applications) to provide identity services (and as Matt points out, security services in general) as part of their offering.</p>
<p><em>&lt;Side Note&gt;No, I do not have a vendetta against Novell, though these last few blog posts may make it feel that way. I actually really like the Novell gang &#8211; Dale, Ben and Nick Nichols among others &#8211; and for the most part completely agree with their views on identity.&lt;/Side Note&gt;</em></p>
<p>Now, I am with Dale for the first half of the article. Developers of these cloud applications just want to focus on the business logic that is at the core of their service, and not have to worry about the plumbing items, which would include identity management. This is fundamental <strong>service-oriented security</strong> principles at play, and the survey Dale mentions reflects this (I would argue that even the one-third of SaaS vendors that said they want to handle identity themselves are either saying so because they don&#8217;t know what&#8217;s involved or are just not happy with what they are getting from the platform and embeddable components). A good set of identity services goes a long way in making applications agile and more acceptable/appealing to customers.</p>
<p>But then the article talks about hosters using identity services as a way to make their platform sticky, because if the platform owns the user accounts for the service, then the service will be hooked. I actually envision the opposite of that when I think of identity services in the platform &#8211; identity services making it possible for the SaaS vendor to switch between platforms easily. What is being described sounds like an Identity Provider, which is a business service, not a platform service.</p>
<p>What the platform should provide, and what most enterprise customers would want, is an <a href="http://bit.ly/cpDs9R">Identity Hub</a> service, as opposed to an Identity Store service. This allows the customer of the SaaS application to plug it into their enterprise identity store (usually a corporate LDAP system, but it could also be their Salesforce user store) and also accept incoming identities over the wire, while still freeing the SaaS vendor from having to manage identities. In this model, the stickiness for the hoster comes not from owning the user accounts, but from the QoS of the identity services they are providing to their customers (the SaaS vendors and their delegated customers). It also doesn&#8217;t force a SaaS vendor to be married to one platform.</p>
<p>Now, I am going to be a little presumptuous here. Having spent some time with Dale, and knowing his past work, I think that he believes in the view I am taking as well. The article seems to be discussing the topic of identity services from a particular angle, which is that there is currently a market opportunity for hosters to leverage the lack of good (non-enterprise) Identity Providers to make their platforms more sticky. It is absolutely true that platforms can (and are actively seeking  to) make themselves sticky by owning the accounts; Dale points out that  this is exactly what Google did by leveraging GMail as the gateway drug  (see, I told you the metaphor works). But as Google seeks to penetrate  the enterprise market deeper, even they are recognizing the need to  support federated identities as a necessary step for viability. (<strong>UPDATE</strong>: An <a href="http://bit.ly/cXkSmU" target="_blank">old blog post</a> of Dale&#8217;s actually clarifies this, and in essence agrees with the view point I am stating here &#8211; exactly as I thought he would <img src='http://blog.talkingidentity.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  )</p>
<p>Bob Blakley has long mused about what business models would make Identity Oracle&#8217;s viable. And the simple truth is that  platform players like Google or Force.com <em>that can leverage an identity-rich business service that they also have</em> are ideally suited to be trusted Identity Providers. But while a big platform player can certainly be a good Identity Provider, not all hosters should need to be Identity Providers to be successful. Instead, standards based identity services would be a great asset for hosters that want to be sticky (by being the best platform to deploy on) without having to take on the onerous task of being an Identity Provider (which has its own challenges) or passing on those responsibilities to their customers (which is what mostly happens today). And it would be an asset for SaaS vendors that want to have the freedom of choice that we all crave, and that want to be able to work with their customers identity infrastructure. As Dale says in the article:</p>
<blockquote><p>You see, people can move an application from one host to another without  much trouble.</p></blockquote>
<p>Now, isn&#8217;t that a good thing, and something that we should be aiming for?</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/cloud-identity-model" rel="tag">Cloud Identity Model</a>, <a href="http://blog.talkingidentity.com/tag/identity-services" rel="tag">Identity Services</a>, <a href="http://blog.talkingidentity.com/tag/saas" rel="tag">SaaS</a>, <a href="http://blog.talkingidentity.com/tag/service-oriented-security" rel="tag">Service-Oriented Security</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DIdentity%2520Services%2520should%2520be%2520like%2520Vitamins%252C%2520not%2520Crack%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fidentity-services-should-be-like-vitamins-not-crack.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fidentity-services-should-be-like-vitamins-not-crack.html%26amp%3Btitle%3DIdentity%2520Services%2520should%2520be%2520like%2520Vitamins%252C%2520not%2520Crack%26amp%3Bbodytext%3DOK%252C%2520so%2520it%2527s%2520a%2520ridiculous%2520title.%2520But%2520hear%2520me%2520out.%250D%250A%250D%250AMatt%2520Flynn%2520brought%2520to%2520my%2520attention%2520an%2520article%2520in%2520which%2520Dale%2520Olds%2520talks%2520about%2520the%2520need%2520for%2520hosters%2520%2528companies%2520that%2520provide%2520the%2520platform%2520on%2520which%2520you%2520deploy%2520your%2520Cloud%252FSaaS%2520applications%2529%2520to%2520provide%2520id';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fidentity-services-should-be-like-vitamins-not-crack.html%26amp%3Bt%3DIdentity%2520Services%2520should%2520be%2520like%2520Vitamins%252C%2520not%2520Crack';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fidentity-services-should-be-like-vitamins-not-crack.html%26amp%3Btitle%3DIdentity%2520Services%2520should%2520be%2520like%2520Vitamins%252C%2520not%2520Crack';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fidentity-services-should-be-like-vitamins-not-crack.html%26amp%3Btitle%3DIdentity%2520Services%2520should%2520be%2520like%2520Vitamins%252C%2520not%2520Crack%26amp%3Bannotation%3DOK%252C%2520so%2520it%2527s%2520a%2520ridiculous%2520title.%2520But%2520hear%2520me%2520out.%250D%250A%250D%250AMatt%2520Flynn%2520brought%2520to%2520my%2520attention%2520an%2520article%2520in%2520which%2520Dale%2520Olds%2520talks%2520about%2520the%2520need%2520for%2520hosters%2520%2528companies%2520that%2520provide%2520the%2520platform%2520on%2520which%2520you%2520deploy%2520your%2520Cloud%252FSaaS%2520applications%2529%2520to%2520provide%2520id';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fidentity-services-should-be-like-vitamins-not-crack.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fidentity-services-should-be-like-vitamins-not-crack.html%26amp%3Btitle%3DIdentity%2520Services%2520should%2520be%2520like%2520Vitamins%252C%2520not%2520Crack%26amp%3Bnotes%3DOK%252C%2520so%2520it%2527s%2520a%2520ridiculous%2520title.%2520But%2520hear%2520me%2520out.%250D%250A%250D%250AMatt%2520Flynn%2520brought%2520to%2520my%2520attention%2520an%2520article%2520in%2520which%2520Dale%2520Olds%2520talks%2520about%2520the%2520need%2520for%2520hosters%2520%2528companies%2520that%2520provide%2520the%2520platform%2520on%2520which%2520you%2520deploy%2520your%2520Cloud%252FSaaS%2520applications%2529%2520to%2520provide%2520id';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fidentity-services-should-be-like-vitamins-not-crack.html%26amp%3Btitle%3DIdentity%2520Services%2520should%2520be%2520like%2520Vitamins%252C%2520not%2520Crack';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fidentity-services-should-be-like-vitamins-not-crack.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fidentity-services-should-be-like-vitamins-not-crack.html%26amp%3Bh%3DIdentity%2520Services%2520should%2520be%2520like%2520Vitamins%252C%2520not%2520Crack';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DIdentity%2520Services%2520should%2520be%2520like%2520Vitamins%252C%2520not%2520Crack%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fidentity-services-should-be-like-vitamins-not-crack.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fidentity-services-should-be-like-vitamins-not-crack.html%2520Identity%2520Services%2520should%2520be%2520like%2520Vitamins%252C%2520not%2520Crack';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DIdentity%2520Services%2520should%2520be%2520like%2520Vitamins%252C%2520not%2520Crack%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fidentity-services-should-be-like-vitamins-not-crack.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/08/identity-services-should-be-like-vitamins-not-crack.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>&#8220;Pull&#8221; is about Evolution, not Revolution</title>
		<link>http://blog.talkingidentity.com/2010/08/pull-is-about-evolution-not-revolution.html</link>
		<comments>http://blog.talkingidentity.com/2010/08/pull-is-about-evolution-not-revolution.html#comments</comments>
		<pubDate>Tue, 10 Aug 2010 15:22:36 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Cat10]]></category>
		<category><![CDATA[Pull-Based Identity]]></category>
		<category><![CDATA[Service-Oriented Security]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1001</guid>
		<description><![CDATA[Ben has responded to my response by vigorously defending his stance against the pull movement. His statement that &#8220;&#8230;this will take more effort than it will return in value&#8221; is correct in identifying what enterprises should focus on &#8211; a cost-benefit analysis &#8211; but not in his estimation of how to do the valuation. I [...]]]></description>
			<content:encoded><![CDATA[<p>Ben has <a href="http://bit.ly/bnnfRk" target="_blank">responded</a> to my <a href="http://bit.ly/bm64Ii" target="_blank">response</a> by vigorously defending his stance against the pull movement. His statement that &#8220;&#8230;this will take more effort than it will return in value&#8221; is correct in identifying what enterprises should focus on &#8211; a cost-benefit analysis &#8211; but not in his estimation of how to do the valuation. I understand the dilemma &#8211; we have something that works; why put in this massive effort to change all that?</p>
<p>(Some would argue &#8211; vigorously &#8211; that what we have actually doesn&#8217;t work. That is a battle for a different post.)</p>
<p>Let me be clear here; no one is saying that you need to throw out what you have, stop implementing IdM with the tools out there, and go back to the drawing board. This is about evolving architecture, not a revolution in technology. As I said in my presentation at Catalyst, enterprises will (probably for a long time) be dealing with both the push-based and the pull-based models. But what enterprises need to recognize (a lot of them already do) is that the pull-based model is the way of the future, starting now. And there are good reasons for it (in fact, Ben&#8217;s post actually points out scenarios where a pull-based model would be far more precise and cost-effective than a push-based model. And isn&#8217;t his last example actually a detective control, not a preventive control?). Enterprises need to start preparing for it now because this is not a transition that can be done overnight. And it is not one they are likely to avoid (or should want to).</p>
<ul>
<li> If an enterprise is considering using cloud services, they need to prepare their IdM infrastructure for a pull-based world, because that is where the majority of cloud services will go (just ask Salesforce)</li>
<li>If a company is offering cloud-based services, they need to be prepared for a pull-based identity model, because that is what major IdPs and enterprises will demand of them (just look at Google Apps Marketplace, or why so many cloud vendors now support SAML and OpenID)</li>
<li>If an enterprise builds applications in-house, they need to understand and prepare for pull-based identity, because the cost of maintaining their applications in the long run will drop significantly (just look at the work we&#8217;re doing with Fusion Applications)</li>
<li>If an enterprise is looking to get out of the business of managing identity and instead wants to rely on 3rd party service providers (including cloud), then they need to focus on pull-based identity to make this happen (just look at the challenges facing Cloud IdM vendors)</li>
</ul>
<p>Ideally, your IdM infrastructure should be able to handle both push and pull based models together (no one wants parallel infrastructure). Ben is correct when he says that he</p>
<blockquote><p>&#8230;would rather not see enterprises cobble their identity  infrastructures together with a little more than hope, bailing wire, and  string. I maintain that enterprises need to build identity on a  sustainable, scalable, identity and access management environment that  is extensible enough to address potential future identity management  models and standards as they arise.</p></blockquote>
<p>I think where I feel differently from Ben is in how quickly we feel these &#8220;potential future identity management  models&#8221; will be here for enterprises to tackle. I am not talking about some Utopian vision that is built on a foundation of sand here (as Ben seems to think). This is a very real change that is happening today. I have spent time with some very smart enterprise architects and program managers who are in the process of building identity services programs in their companies today that are built on this view. Within Oracle itself, Fusion Applications is a major undertaking that builds on this vision by leveraging identity standards, and the knowledge we gain from the effort is guiding our involvement in driving these standards forward.</p>
<p>Yes, there are unresolved challenges, but all of the identity standards are still evolving (though sometimes slower than we would like). The vision of <strong>Service-Oriented Security</strong> (which is built around pull-based identity) is a guiding force that is helping create a cohesive vision around which to rationalize the various standards efforts (which all too often have been disjointed), resulting in a better framework to build applications on. And it is well established at this point that application development is all about frameworks now (no one builds applications from the ground up any more).</p>
<p>By the way, I will be doing a <a href="http://bit.ly/9soO21" target="_blank">live webcast</a> on Service-Oriented Security on August 25 at 2pm ET/11am PT. A lot of what we are talking about here will be discussed during the webcast in far more detail. So <a href="http://bit.ly/9soO21" target="_blank">register now</a> and we can chat about the challenges and promise of pull during the webcast.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/cat10" rel="tag">Cat10</a>, <a href="http://blog.talkingidentity.com/tag/pull-based-identity" rel="tag">Pull-Based Identity</a>, <a href="http://blog.talkingidentity.com/tag/service-oriented-security" rel="tag">Service-Oriented Security</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3D%2522Pull%2522%2520is%2520about%2520Evolution%252C%2520not%2520Revolution%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpull-is-about-evolution-not-revolution.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpull-is-about-evolution-not-revolution.html%26amp%3Btitle%3D%2522Pull%2522%2520is%2520about%2520Evolution%252C%2520not%2520Revolution%26amp%3Bbodytext%3DBen%2520has%2520responded%2520to%2520my%2520response%2520by%2520vigorously%2520defending%2520his%2520stance%2520against%2520the%2520pull%2520movement.%2520His%2520statement%2520that%2520%2522...this%2520will%2520take%2520more%2520effort%2520than%2520it%2520will%2520return%2520in%2520value%2522%2520is%2520correct%2520in%2520identifying%2520what%2520enterprises%2520should%2520focus%2520on%2520-%2520a%2520cost-benefit';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpull-is-about-evolution-not-revolution.html%26amp%3Bt%3D%2522Pull%2522%2520is%2520about%2520Evolution%252C%2520not%2520Revolution';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpull-is-about-evolution-not-revolution.html%26amp%3Btitle%3D%2522Pull%2522%2520is%2520about%2520Evolution%252C%2520not%2520Revolution';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpull-is-about-evolution-not-revolution.html%26amp%3Btitle%3D%2522Pull%2522%2520is%2520about%2520Evolution%252C%2520not%2520Revolution%26amp%3Bannotation%3DBen%2520has%2520responded%2520to%2520my%2520response%2520by%2520vigorously%2520defending%2520his%2520stance%2520against%2520the%2520pull%2520movement.%2520His%2520statement%2520that%2520%2522...this%2520will%2520take%2520more%2520effort%2520than%2520it%2520will%2520return%2520in%2520value%2522%2520is%2520correct%2520in%2520identifying%2520what%2520enterprises%2520should%2520focus%2520on%2520-%2520a%2520cost-benefit';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpull-is-about-evolution-not-revolution.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpull-is-about-evolution-not-revolution.html%26amp%3Btitle%3D%2522Pull%2522%2520is%2520about%2520Evolution%252C%2520not%2520Revolution%26amp%3Bnotes%3DBen%2520has%2520responded%2520to%2520my%2520response%2520by%2520vigorously%2520defending%2520his%2520stance%2520against%2520the%2520pull%2520movement.%2520His%2520statement%2520that%2520%2522...this%2520will%2520take%2520more%2520effort%2520than%2520it%2520will%2520return%2520in%2520value%2522%2520is%2520correct%2520in%2520identifying%2520what%2520enterprises%2520should%2520focus%2520on%2520-%2520a%2520cost-benefit';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpull-is-about-evolution-not-revolution.html%26amp%3Btitle%3D%2522Pull%2522%2520is%2520about%2520Evolution%252C%2520not%2520Revolution';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpull-is-about-evolution-not-revolution.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpull-is-about-evolution-not-revolution.html%26amp%3Bh%3D%2522Pull%2522%2520is%2520about%2520Evolution%252C%2520not%2520Revolution';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3D%2522Pull%2522%2520is%2520about%2520Evolution%252C%2520not%2520Revolution%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpull-is-about-evolution-not-revolution.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpull-is-about-evolution-not-revolution.html%2520%2522Pull%2522%2520is%2520about%2520Evolution%252C%2520not%2520Revolution';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3D%2522Pull%2522%2520is%2520about%2520Evolution%252C%2520not%2520Revolution%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpull-is-about-evolution-not-revolution.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/08/pull-is-about-evolution-not-revolution.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>&#8220;Push vs Pull&#8221; in Identity Management</title>
		<link>http://blog.talkingidentity.com/2010/08/push-vs-pull-in-identity-management.html</link>
		<comments>http://blog.talkingidentity.com/2010/08/push-vs-pull-in-identity-management.html#comments</comments>
		<pubDate>Thu, 05 Aug 2010 19:40:08 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Cat10]]></category>
		<category><![CDATA[JIT Provisioning]]></category>
		<category><![CDATA[Just-In-Time Provisioning]]></category>
		<category><![CDATA[Service-Oriented Security]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=989</guid>
		<description><![CDATA[My friend Ben Goodman over at Novell recently wrote a blog post arguing against the &#8220;future of identity is pull&#8221; movement that seems to be sweeping the nation (well, at least the hallways at the recent Catalyst conference). I&#8217;ll give him credit for having the conviction to go against the grain here, since the idea [...]]]></description>
			<content:encoded><![CDATA[<p>My friend Ben Goodman over at Novell recently wrote <a href="http://bit.ly/bR5TVQ" target="_blank">a blog post</a> arguing against the &#8220;<em>future of identity is pull</em>&#8221; movement that seems to be sweeping the nation (well, at least the hallways at the recent Catalyst conference). I&#8217;ll give him credit for having the conviction to go against the grain here, since the idea of pull really resonated with the attendees at the conference (In my presentation, I quipped that &#8220;We are entering the &#8216;<em>Age of Pull</em>&#8216;, where services are king, and Bob Blakley is our prophet&#8221;). Now, I can&#8217;t make the case for pull any better than folks like Bob already have. But the foundation for Ben&#8217;s argument seems to be in his taking a pragmatist&#8217;s view of the world, which is the right view to take. I just happen to end up drawing different conclusions from that same view.</p>
<p>As I detailed in my Catalyst talk, identity management has always been a very reactionary technological domain, influenced by the environment (architectural, regulatory) that it exists within. And the &#8220;pull&#8221; model is coming into its own because of two key factors driving next-gen application architectures &#8211; <em>Identity Externalization</em> and <em>Federation/Cloud</em>. Push architectures are built on the almost contradictory principles of guesswork and predictability &#8211; You have to guess ahead of time what it is that needs to be pushed to the target, and you have to rely on all flows and scenarios using identity data to be predictable within the use cases you have envisioned. Because of this, push forces us to overshare identity data on the off chance that something might be needed. But technology, and more importantly business, has advanced (on the back of standards) to the point where dynamism and flexibility are not only possible but expected and relied on. And concerns for privacy and regulatory compliance are forcing enterprises to re-evaluate how free they are in sharing identity data. In such an environment, the principles behind push are hopelessly outdated.</p>
<div class="wp-caption alignnone" style="width: 510px"><a href="http://bit.ly/caWNvG" target="_blank"><img title="Speaking at Catalyst" src="http://farm5.static.flickr.com/4098/4854361392_af916a8f80.jpg" alt="Me speaking at Burton Catalyst 2010 (image courtesy Ian Glazer)" width="500" height="335" /></a><p class="wp-caption-text">Me speaking at Burton Catalyst 2010 (image courtesy Ian Glazer)</p></div>
<p><strong>Service-Oriented Security</strong> is not externalization just for the sake of it. It brings great benefits in terms of agility (reuse over duplication), consistency (same policies applied across environments) and collaboration (across application, domain and enterprise boundaries). And if you look at how identity management has become more process oriented (an argument Ben uses for the push model), you realize that a lot of that process exists because we need to push identity data into the targets. The move to pull is not just about technology and integration architectures, it is also about streamlining and optimizing business controls that had to be put in place because of the way we leverage identity data in applications.</p>
<p>Push is never going to disappear &#8211; the complexity of our enterprise environments all but assures that. But as I tried to demonstrate in my provisioning session, the idea is to transition to where you make the choice of model most appropriate to the business needs of the application. Push from the HR system to an Identity Store will likely still exist, and further push to complex ERP style applications may also continue. But the majority of applications will get streamlined to leverage external services, including authentication, authorization and identity services, with minimal need for local storage of identity data or authorization metadata.</p>
<p>It is important to note (as we discuss issues like performance) that pull doesn&#8217;t only mean centralized, externalized identity stores, though ideally that is the goal. Push vs Pull is also about which party is initiating data transfer. A large cloud provider like Salesforce really doesn&#8217;t want its enterprise customers to push all their identity data to them all the time. At the same time, it is likely not going to want to <em>pull</em> data across the internet from its customers identity stores every time it needs it. But it can (and will) decide when and how to <em>pull</em> data from those identity stores into its local run-time store (cache, if you will). This is still a &#8220;pull&#8221; model, though not necessarily externalized identity. It is, however, a necessary facet of our increasingly distributed IT infrastructure, and one at the heart of the <strong>Just-In-Time Pull-based Provisioning</strong> I described in my talk.</p>
<div id="attachment_992" class="wp-caption alignnone" style="width: 560px"><img class="size-full wp-image-992" title="JIT-Prov_w_Pull" src="http://blog.talkingidentity.com/wp-content/uploads/2010/08/JIT-Prov_w_Pull.jpg" alt="JIT Provisioning with OAuth &amp; IGF-based Identity Pull" width="550" height="306" /><p class="wp-caption-text">JIT Provisioning with OAuth &amp; IGF-based Identity Pull</p></div>
<p>Through all this, keep in mind that standardizing identity pull is a far easier task than standardizing identity push (where there were way too many targets to influence, and SPML failed to make headway). And that will go a long way in driving adoption, especially as identity services makes its way into the platforms that applications are being built on. Given that Oracle has a stake in all parts of the equation &#8211; the identity products, the middleware platform and the applications built on top of them &#8211; we have unique insight into this aspect of the future of identity that makes me far more confident in making this assertion.</p>
<p>The way I see it, the pull model is the logical next step needed to power the upcoming enterprise application environment where mashups and loose connections are going to be more common and hard-coded integrations are going to be hard to justify.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/cat10" rel="tag">Cat10</a>, <a href="http://blog.talkingidentity.com/tag/jit-provisioning" rel="tag">JIT Provisioning</a>, <a href="http://blog.talkingidentity.com/tag/just-in-time-provisioning" rel="tag">Just-In-Time Provisioning</a>, <a href="http://blog.talkingidentity.com/tag/service-oriented-security" rel="tag">Service-Oriented Security</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3D%2522Push%2520vs%2520Pull%2522%2520in%2520Identity%2520Management%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpush-vs-pull-in-identity-management.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpush-vs-pull-in-identity-management.html%26amp%3Btitle%3D%2522Push%2520vs%2520Pull%2522%2520in%2520Identity%2520Management%26amp%3Bbodytext%3DMy%2520friend%2520Ben%2520Goodman%2520over%2520at%2520Novell%2520recently%2520wrote%2520a%2520blog%2520post%2520arguing%2520against%2520the%2520%2522future%2520of%2520identity%2520is%2520pull%2522%2520movement%2520that%2520seems%2520to%2520be%2520sweeping%2520the%2520nation%2520%2528well%252C%2520at%2520least%2520the%2520hallways%2520at%2520the%2520recent%2520Catalyst%2520conference%2529.%2520I%2527ll%2520give%2520him%2520credit%2520for%2520h';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpush-vs-pull-in-identity-management.html%26amp%3Bt%3D%2522Push%2520vs%2520Pull%2522%2520in%2520Identity%2520Management';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpush-vs-pull-in-identity-management.html%26amp%3Btitle%3D%2522Push%2520vs%2520Pull%2522%2520in%2520Identity%2520Management';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpush-vs-pull-in-identity-management.html%26amp%3Btitle%3D%2522Push%2520vs%2520Pull%2522%2520in%2520Identity%2520Management%26amp%3Bannotation%3DMy%2520friend%2520Ben%2520Goodman%2520over%2520at%2520Novell%2520recently%2520wrote%2520a%2520blog%2520post%2520arguing%2520against%2520the%2520%2522future%2520of%2520identity%2520is%2520pull%2522%2520movement%2520that%2520seems%2520to%2520be%2520sweeping%2520the%2520nation%2520%2528well%252C%2520at%2520least%2520the%2520hallways%2520at%2520the%2520recent%2520Catalyst%2520conference%2529.%2520I%2527ll%2520give%2520him%2520credit%2520for%2520h';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpush-vs-pull-in-identity-management.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpush-vs-pull-in-identity-management.html%26amp%3Btitle%3D%2522Push%2520vs%2520Pull%2522%2520in%2520Identity%2520Management%26amp%3Bnotes%3DMy%2520friend%2520Ben%2520Goodman%2520over%2520at%2520Novell%2520recently%2520wrote%2520a%2520blog%2520post%2520arguing%2520against%2520the%2520%2522future%2520of%2520identity%2520is%2520pull%2522%2520movement%2520that%2520seems%2520to%2520be%2520sweeping%2520the%2520nation%2520%2528well%252C%2520at%2520least%2520the%2520hallways%2520at%2520the%2520recent%2520Catalyst%2520conference%2529.%2520I%2527ll%2520give%2520him%2520credit%2520for%2520h';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpush-vs-pull-in-identity-management.html%26amp%3Btitle%3D%2522Push%2520vs%2520Pull%2522%2520in%2520Identity%2520Management';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpush-vs-pull-in-identity-management.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpush-vs-pull-in-identity-management.html%26amp%3Bh%3D%2522Push%2520vs%2520Pull%2522%2520in%2520Identity%2520Management';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3D%2522Push%2520vs%2520Pull%2522%2520in%2520Identity%2520Management%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpush-vs-pull-in-identity-management.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpush-vs-pull-in-identity-management.html%2520%2522Push%2520vs%2520Pull%2522%2520in%2520Identity%2520Management';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3D%2522Push%2520vs%2520Pull%2522%2520in%2520Identity%2520Management%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F08%252Fpush-vs-pull-in-identity-management.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/08/push-vs-pull-in-identity-management.html/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Beyond SPML: Access Provisioning in a Services World</title>
		<link>http://blog.talkingidentity.com/2010/07/beyond-spml-access-provisioning-in-a-services-world.html</link>
		<comments>http://blog.talkingidentity.com/2010/07/beyond-spml-access-provisioning-in-a-services-world.html#comments</comments>
		<pubDate>Fri, 30 Jul 2010 19:30:03 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Burton Catalyst Conference]]></category>
		<category><![CDATA[Cat10]]></category>
		<category><![CDATA[Federated Provisioning]]></category>
		<category><![CDATA[Provisioning]]></category>
		<category><![CDATA[SPML]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=977</guid>
		<description><![CDATA[Another Burton Group Catalyst conference has come to a close, and as always it was a treasure trove of stories, ideas and conversations. Which is why it was great to have the uncertainty around the conference laid to rest when it was announced that it will be back next year (July 26-29 in San Diego, [...]]]></description>
			<content:encoded><![CDATA[<p>Another <strong>Burton Group Catalyst</strong> conference has come to a close, and as always it was a treasure trove of stories, ideas and conversations. Which is why it was great to have the uncertainty around the conference laid to rest when it was announced that it will be back next year (July 26-29 in San Diego, mark your calendars). I spent most of my time in the identity management and privacy track, with some forays into social media and cloud tracks. I will try to write up some of the more interesting things I heard over the next few posts, but you can definitely check out <a href="http://bit.ly/aGHded" target="_blank">my tweetstream</a> and the <a href="http://bit.ly/8XXcaZ" target="_blank">conference tweetstream</a> for an unstructured view.</p>
<p>On Wednesday, I gave a talk entitled &#8220;<strong>Beyond SPML: Access Provisioning in a Services World</strong>&#8221; which built on my <a href="http://bit.ly/b4aokt">Gluecon talk</a> and work with Fusion architecture to provide a vision for the future of provisioning. The central thesis is that as we move from <em>Push</em> to <em>Pull</em> models in Identity, provisioning becomes a key component in making sure that policy and process controls are still enforced. But this requires a fundamental evolution in application and middleware architecture towards services-oriented security and externalized identity.</p>
<div id="__ss_4873777" style="width: 550px;"><object id="__sse4873777" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="550" height="460" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=1722kaushik-100730120956-phpapp02&amp;stripped_title=beyond-spml-access-provisioning-in-a-services-world" /><param name="name" value="__sse4873777" /><param name="allowfullscreen" value="true" /><embed id="__sse4873777" type="application/x-shockwave-flash" width="550" height="460" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=1722kaushik-100730120956-phpapp02&amp;stripped_title=beyond-spml-access-provisioning-in-a-services-world" name="__sse4873777" allowscriptaccess="always" allowfullscreen="true"></embed></object></div>
<p>I was extremely gratified to receive lots of positive validation and feedback about the vision I expressed in my presentation. And it really fit in with the theme flowing through the presentations in the provisioning section, which was focused on moving to a more streamlined, manageable, scalable provisioning future. It also echoed sentiment that provisioning is a multi-faceted problem with different interaction points and flows and will therefore require a combination of standards rather than just one standard. This was really driven home by the extremely interactive SPML SIG meeting that I participated in (organized by Mark Diodati) where there was generally agreement that SPML needs to get really focused on specific use cases rather than trying to be all things to all possibilities.</p>
<p>I am looking  for input, so check out the deck and leave me comments on this post. I will definitely be building on the ideas in there with our identity management team to move the vision of service-oriented security forward. But for it to be useful, it has to resonate with the IdM and application development communities. And that&#8217;s where we all have to work together in making this a reality.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/burton-catalyst-conference" rel="tag">Burton Catalyst Conference</a>, <a href="http://blog.talkingidentity.com/tag/cat10" rel="tag">Cat10</a>, <a href="http://blog.talkingidentity.com/tag/federated-provisioning" rel="tag">Federated Provisioning</a>, <a href="http://blog.talkingidentity.com/tag/provisioning" rel="tag">Provisioning</a>, <a href="http://blog.talkingidentity.com/tag/spml" rel="tag">SPML</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DBeyond%2520SPML%253A%2520Access%2520Provisioning%2520in%2520a%2520Services%2520World%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fbeyond-spml-access-provisioning-in-a-services-world.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fbeyond-spml-access-provisioning-in-a-services-world.html%26amp%3Btitle%3DBeyond%2520SPML%253A%2520Access%2520Provisioning%2520in%2520a%2520Services%2520World%26amp%3Bbodytext%3DAnother%2520Burton%2520Group%2520Catalyst%2520conference%2520has%2520come%2520to%2520a%2520close%252C%2520and%2520as%2520always%2520it%2520was%2520a%2520treasure%2520trove%2520of%2520stories%252C%2520ideas%2520and%2520conversations.%2520Which%2520is%2520why%2520it%2520was%2520great%2520to%2520have%2520the%2520uncertainty%2520around%2520the%2520conference%2520laid%2520to%2520rest%2520when%2520it%2520was%2520announced%2520that%2520i';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fbeyond-spml-access-provisioning-in-a-services-world.html%26amp%3Bt%3DBeyond%2520SPML%253A%2520Access%2520Provisioning%2520in%2520a%2520Services%2520World';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fbeyond-spml-access-provisioning-in-a-services-world.html%26amp%3Btitle%3DBeyond%2520SPML%253A%2520Access%2520Provisioning%2520in%2520a%2520Services%2520World';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fbeyond-spml-access-provisioning-in-a-services-world.html%26amp%3Btitle%3DBeyond%2520SPML%253A%2520Access%2520Provisioning%2520in%2520a%2520Services%2520World%26amp%3Bannotation%3DAnother%2520Burton%2520Group%2520Catalyst%2520conference%2520has%2520come%2520to%2520a%2520close%252C%2520and%2520as%2520always%2520it%2520was%2520a%2520treasure%2520trove%2520of%2520stories%252C%2520ideas%2520and%2520conversations.%2520Which%2520is%2520why%2520it%2520was%2520great%2520to%2520have%2520the%2520uncertainty%2520around%2520the%2520conference%2520laid%2520to%2520rest%2520when%2520it%2520was%2520announced%2520that%2520i';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fbeyond-spml-access-provisioning-in-a-services-world.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fbeyond-spml-access-provisioning-in-a-services-world.html%26amp%3Btitle%3DBeyond%2520SPML%253A%2520Access%2520Provisioning%2520in%2520a%2520Services%2520World%26amp%3Bnotes%3DAnother%2520Burton%2520Group%2520Catalyst%2520conference%2520has%2520come%2520to%2520a%2520close%252C%2520and%2520as%2520always%2520it%2520was%2520a%2520treasure%2520trove%2520of%2520stories%252C%2520ideas%2520and%2520conversations.%2520Which%2520is%2520why%2520it%2520was%2520great%2520to%2520have%2520the%2520uncertainty%2520around%2520the%2520conference%2520laid%2520to%2520rest%2520when%2520it%2520was%2520announced%2520that%2520i';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fbeyond-spml-access-provisioning-in-a-services-world.html%26amp%3Btitle%3DBeyond%2520SPML%253A%2520Access%2520Provisioning%2520in%2520a%2520Services%2520World';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fbeyond-spml-access-provisioning-in-a-services-world.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fbeyond-spml-access-provisioning-in-a-services-world.html%26amp%3Bh%3DBeyond%2520SPML%253A%2520Access%2520Provisioning%2520in%2520a%2520Services%2520World';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DBeyond%2520SPML%253A%2520Access%2520Provisioning%2520in%2520a%2520Services%2520World%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fbeyond-spml-access-provisioning-in-a-services-world.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fbeyond-spml-access-provisioning-in-a-services-world.html%2520Beyond%2520SPML%253A%2520Access%2520Provisioning%2520in%2520a%2520Services%2520World';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DBeyond%2520SPML%253A%2520Access%2520Provisioning%2520in%2520a%2520Services%2520World%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fbeyond-spml-access-provisioning-in-a-services-world.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/07/beyond-spml-access-provisioning-in-a-services-world.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Time to Catalyse Some Change in Provisioning</title>
		<link>http://blog.talkingidentity.com/2010/07/time-to-catalyse-some-change-in-provisioning.html</link>
		<comments>http://blog.talkingidentity.com/2010/07/time-to-catalyse-some-change-in-provisioning.html#comments</comments>
		<pubDate>Tue, 27 Jul 2010 17:57:43 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Burton Catalyst Conference]]></category>
		<category><![CDATA[BurtonGroupCatalyst10]]></category>
		<category><![CDATA[Cat10]]></category>
		<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[Provisioning]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=972</guid>
		<description><![CDATA[It&#8217;s Burton Group Catalyst time again, and I will be pushing forward in my quest to advance access provisioning to the next level. I will be giving a talk on &#8220;Beyond SPML: Access Provisioning in a Services World&#8221; tomorrow (Wednesday, July 28 2010) at 11:20 am, part of the &#8220;provisioning needs to change&#8221; block (it [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s Burton Group Catalyst time again, and I will be pushing forward in my quest to advance access provisioning to the next level. I will be giving a talk on &#8220;<strong>Beyond SPML: Access Provisioning in a Services World</strong>&#8221; tomorrow (Wednesday, July 28 2010) at 11:20 am, part of the &#8220;provisioning needs to change&#8221; block (it would seem). I will be building on the ideas I presented at Gluecon and in my ensuing <a href="http://bit.ly/b4aokt">blog series</a>.</p>
<p>Please note that the rooms for the different tracks at Catalyst were switched, with IdPS moving to <strong>Sapphire AB</strong>. So if you were going off the information Oracle sent out, or the Oracle Hospitality Suite invite in your Catalyst registration bag, then please note that my session will not be in Sapphire CD, but will be in Sapphire AB instead.</p>
<p>And be sure to drop by the Oracle Hospitality Suite in <strong>Aqua 308</strong> on Wednesday evening to check out the 11g demos, enjoy some good food and drink, and hang out with some of the cool cats of Oracle Identity Management (and me!).</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/burton-catalyst-conference" rel="tag">Burton Catalyst Conference</a>, <a href="http://blog.talkingidentity.com/tag/burtongroupcatalyst10" rel="tag">BurtonGroupCatalyst10</a>, <a href="http://blog.talkingidentity.com/tag/cat10" rel="tag">Cat10</a>, <a href="http://blog.talkingidentity.com/tag/oracle-identity-management" rel="tag">Oracle Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/provisioning" rel="tag">Provisioning</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DTime%2520to%2520Catalyse%2520Some%2520Change%2520in%2520Provisioning%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Ftime-to-catalyse-some-change-in-provisioning.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Ftime-to-catalyse-some-change-in-provisioning.html%26amp%3Btitle%3DTime%2520to%2520Catalyse%2520Some%2520Change%2520in%2520Provisioning%26amp%3Bbodytext%3DIt%2527s%2520Burton%2520Group%2520Catalyst%2520time%2520again%252C%2520and%2520I%2520will%2520be%2520pushing%2520forward%2520in%2520my%2520quest%2520to%2520advance%2520access%2520provisioning%2520to%2520the%2520next%2520level.%2520I%2520will%2520be%2520giving%2520a%2520talk%2520on%2520%2522Beyond%2520SPML%253A%2520Access%2520Provisioning%2520in%2520a%2520Services%2520World%2522%2520tomorrow%2520%2528Wednesday%252C%2520July%252028%25202010%2529%2520at';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Ftime-to-catalyse-some-change-in-provisioning.html%26amp%3Bt%3DTime%2520to%2520Catalyse%2520Some%2520Change%2520in%2520Provisioning';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Ftime-to-catalyse-some-change-in-provisioning.html%26amp%3Btitle%3DTime%2520to%2520Catalyse%2520Some%2520Change%2520in%2520Provisioning';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Ftime-to-catalyse-some-change-in-provisioning.html%26amp%3Btitle%3DTime%2520to%2520Catalyse%2520Some%2520Change%2520in%2520Provisioning%26amp%3Bannotation%3DIt%2527s%2520Burton%2520Group%2520Catalyst%2520time%2520again%252C%2520and%2520I%2520will%2520be%2520pushing%2520forward%2520in%2520my%2520quest%2520to%2520advance%2520access%2520provisioning%2520to%2520the%2520next%2520level.%2520I%2520will%2520be%2520giving%2520a%2520talk%2520on%2520%2522Beyond%2520SPML%253A%2520Access%2520Provisioning%2520in%2520a%2520Services%2520World%2522%2520tomorrow%2520%2528Wednesday%252C%2520July%252028%25202010%2529%2520at';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Ftime-to-catalyse-some-change-in-provisioning.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Ftime-to-catalyse-some-change-in-provisioning.html%26amp%3Btitle%3DTime%2520to%2520Catalyse%2520Some%2520Change%2520in%2520Provisioning%26amp%3Bnotes%3DIt%2527s%2520Burton%2520Group%2520Catalyst%2520time%2520again%252C%2520and%2520I%2520will%2520be%2520pushing%2520forward%2520in%2520my%2520quest%2520to%2520advance%2520access%2520provisioning%2520to%2520the%2520next%2520level.%2520I%2520will%2520be%2520giving%2520a%2520talk%2520on%2520%2522Beyond%2520SPML%253A%2520Access%2520Provisioning%2520in%2520a%2520Services%2520World%2522%2520tomorrow%2520%2528Wednesday%252C%2520July%252028%25202010%2529%2520at';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Ftime-to-catalyse-some-change-in-provisioning.html%26amp%3Btitle%3DTime%2520to%2520Catalyse%2520Some%2520Change%2520in%2520Provisioning';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Ftime-to-catalyse-some-change-in-provisioning.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Ftime-to-catalyse-some-change-in-provisioning.html%26amp%3Bh%3DTime%2520to%2520Catalyse%2520Some%2520Change%2520in%2520Provisioning';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DTime%2520to%2520Catalyse%2520Some%2520Change%2520in%2520Provisioning%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Ftime-to-catalyse-some-change-in-provisioning.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Ftime-to-catalyse-some-change-in-provisioning.html%2520Time%2520to%2520Catalyse%2520Some%2520Change%2520in%2520Provisioning';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DTime%2520to%2520Catalyse%2520Some%2520Change%2520in%2520Provisioning%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Ftime-to-catalyse-some-change-in-provisioning.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/07/time-to-catalyse-some-change-in-provisioning.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Challenge of Security Questions</title>
		<link>http://blog.talkingidentity.com/2010/07/the-challenge-of-security-questions.html</link>
		<comments>http://blog.talkingidentity.com/2010/07/the-challenge-of-security-questions.html#comments</comments>
		<pubDate>Thu, 22 Jul 2010 20:23:27 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[Identity Proofing]]></category>
		<category><![CDATA[Knowledge-Based Authentication]]></category>
		<category><![CDATA[OAAM]]></category>
		<category><![CDATA[OIM]]></category>
		<category><![CDATA[Oracle Identity Management 11g]]></category>
		<category><![CDATA[Password Management]]></category>
		<category><![CDATA[Password Recovery Techniques]]></category>
		<category><![CDATA[Security Questions]]></category>
		<category><![CDATA[Service-Oriented Security]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=966</guid>
		<description><![CDATA[Jackson Shaw just wrote about a website called goodsecurityquestions.com. As the name indicates, it&#8217;s a site that purports to distinguish between good and bad questions to employ when setting up for your identity re-verification challenges (for when you forget your password or need to execute a high-value transaction, for instance). The same site also (correctly) [...]]]></description>
			<content:encoded><![CDATA[<p>Jackson Shaw just <a href="http://jacksonshaw.blogspot.com/2010/07/what-are-good-security-questions-for.html" target="_blank">wrote about</a> a website called <a href="http://bit.ly/9ZrPKT" target="_blank">goodsecurityquestions.com</a>. As the name indicates, it&#8217;s a site that purports to distinguish between good and bad questions to employ when setting up for your identity re-verification challenges (for when you forget your password or need to execute a high-value transaction, for instance). The same site also (correctly) points out that <a href="http://bit.ly/8Y1r7L" target="_blank">there are no good security questions</a> (due to the inherent security issues in it), just better ones, based on the following criteria:</p>
<ol>
<li>The answer cannot be easily guessed or researched [<em>Safe</em>]</li>
<li>The answer doesn&#8217;t change over time [<em>Stable</em>]</li>
<li>The answer is memorable [<em>Recall-ability</em>]</li>
<li>The answer is definitive or simple [<em>Simplicity</em>]</li>
</ol>
<p>Good criteria to remember next time you are deciding between &#8220;What is your pet&#8217;s name?&#8221; and &#8220;What was the name of your first stuffed animal?&#8221;.</p>
<p>Of course, the service you are interacting with needs to allow you to choose from a large enough set or supply your own questions so you can adhere to this principle. And a highly sensitive application should go beyond just plain security questions. While most services are moving towards simpler yet more secure mechanisms &#8211; emailing the user short-lived password reset tokens, for instance &#8211; there are many cases where you still need a challenge-based mechanism (like when the forgotten password is the one used to access your email).</p>
<p><strong>Knowledge-Based Authentication </strong>has gotten increasingly sophisticated over the last few years, and enterprises looking to leverage this can do better than just providing their users a few hard-coded questions to choose from. <a href="http://bit.ly/9njEb1" target="_blank"><strong>Oracle Adaptive Access Manager 11g</strong></a> brings features like <em>Answer Logic</em> (which employs fuzzy logic to increase the usability of security questions) and <em>One-Time Passwords</em> (delivered via SMS, email, IM or voice) into the mix, while also adding real-time risk analytics to make the overall process more secure, reliable, usable and cost-effective.</p>
<p>And all of this is delivered as a service so that enterprises can incorporate KBA into their various applications as needed. In fact, as part of the suite-wide integration design theme of Oracle Identity Management 11g, OAAM now has out-of-the-box integrations with Oracle Identity Manager and Oracle Access Manager. So if you deploy the suite, the real-time risk analytics and risk-based challenge mechanisms of OAAM are automatically leveraged by those other products. It is a sweet thing to behold.</p>
<p>Even as we <a href="http://bit.ly/cK78jV" target="_blank">sound out the call to kill passwords</a> (an NPT for passwords; I like that), KBA will continue to be a critical tool in the identity proofing arena. So keep an eye out for all the innovation that will take place in this field.</p>
<p><a href="http://www.geekculture.com/joyoftech/joyarchives/001_300/163.html"><img class="alignnone size-full wp-image-968" title="Password Retrieval" src="http://blog.talkingidentity.com/wp-content/uploads/2010/07/ForgotPassword.gif" alt="Password Retrieval" width="469" height="358" /></a></p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/identity-proofing" rel="tag">Identity Proofing</a>, <a href="http://blog.talkingidentity.com/tag/knowledge-based-authentication" rel="tag">Knowledge-Based Authentication</a>, <a href="http://blog.talkingidentity.com/tag/oaam" rel="tag">OAAM</a>, <a href="http://blog.talkingidentity.com/tag/oim" rel="tag">OIM</a>, <a href="http://blog.talkingidentity.com/tag/oracle-identity-management" rel="tag">Oracle Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/oracle-identity-management-11g" rel="tag">Oracle Identity Management 11g</a>, <a href="http://blog.talkingidentity.com/tag/password-management" rel="tag">Password Management</a>, <a href="http://blog.talkingidentity.com/tag/password-recovery-techniques" rel="tag">Password Recovery Techniques</a>, <a href="http://blog.talkingidentity.com/tag/security-questions" rel="tag">Security Questions</a>, <a href="http://blog.talkingidentity.com/tag/service-oriented-security" rel="tag">Service-Oriented Security</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DThe%2520Challenge%2520of%2520Security%2520Questions%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fthe-challenge-of-security-questions.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fthe-challenge-of-security-questions.html%26amp%3Btitle%3DThe%2520Challenge%2520of%2520Security%2520Questions%26amp%3Bbodytext%3DJackson%2520Shaw%2520just%2520wrote%2520about%2520a%2520website%2520called%2520goodsecurityquestions.com.%2520As%2520the%2520name%2520indicates%252C%2520it%2527s%2520a%2520site%2520that%2520purports%2520to%2520distinguish%2520between%2520good%2520and%2520bad%2520questions%2520to%2520employ%2520when%2520setting%2520up%2520for%2520your%2520identity%2520re-verification%2520challenges%2520%2528for%2520when%2520';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fthe-challenge-of-security-questions.html%26amp%3Bt%3DThe%2520Challenge%2520of%2520Security%2520Questions';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fthe-challenge-of-security-questions.html%26amp%3Btitle%3DThe%2520Challenge%2520of%2520Security%2520Questions';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fthe-challenge-of-security-questions.html%26amp%3Btitle%3DThe%2520Challenge%2520of%2520Security%2520Questions%26amp%3Bannotation%3DJackson%2520Shaw%2520just%2520wrote%2520about%2520a%2520website%2520called%2520goodsecurityquestions.com.%2520As%2520the%2520name%2520indicates%252C%2520it%2527s%2520a%2520site%2520that%2520purports%2520to%2520distinguish%2520between%2520good%2520and%2520bad%2520questions%2520to%2520employ%2520when%2520setting%2520up%2520for%2520your%2520identity%2520re-verification%2520challenges%2520%2528for%2520when%2520';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fthe-challenge-of-security-questions.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fthe-challenge-of-security-questions.html%26amp%3Btitle%3DThe%2520Challenge%2520of%2520Security%2520Questions%26amp%3Bnotes%3DJackson%2520Shaw%2520just%2520wrote%2520about%2520a%2520website%2520called%2520goodsecurityquestions.com.%2520As%2520the%2520name%2520indicates%252C%2520it%2527s%2520a%2520site%2520that%2520purports%2520to%2520distinguish%2520between%2520good%2520and%2520bad%2520questions%2520to%2520employ%2520when%2520setting%2520up%2520for%2520your%2520identity%2520re-verification%2520challenges%2520%2528for%2520when%2520';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fthe-challenge-of-security-questions.html%26amp%3Btitle%3DThe%2520Challenge%2520of%2520Security%2520Questions';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fthe-challenge-of-security-questions.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fthe-challenge-of-security-questions.html%26amp%3Bh%3DThe%2520Challenge%2520of%2520Security%2520Questions';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DThe%2520Challenge%2520of%2520Security%2520Questions%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fthe-challenge-of-security-questions.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fthe-challenge-of-security-questions.html%2520The%2520Challenge%2520of%2520Security%2520Questions';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DThe%2520Challenge%2520of%2520Security%2520Questions%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fthe-challenge-of-security-questions.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/07/the-challenge-of-security-questions.html/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Announcing Oracle Identity Management 11g</title>
		<link>http://blog.talkingidentity.com/2010/07/announcing-oracle-identity-management-11g.html</link>
		<comments>http://blog.talkingidentity.com/2010/07/announcing-oracle-identity-management-11g.html#comments</comments>
		<pubDate>Wed, 21 Jul 2010 19:00:33 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[Oracle Identity Management 11g]]></category>
		<category><![CDATA[Service-Oriented Security]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=961</guid>
		<description><![CDATA[Well, the press release went out a few hours ago, and the launch webcast just finished minutes ago, announcing the arrival of Oracle Identity Management 11g, the next phase in our rollout of the most complete, integrated and open suite of identity management products. As Amit Jasuja shared in the webcast, there is over 750 [...]]]></description>
			<content:encoded><![CDATA[<p>Well, the <a href="http://bit.ly/aT4vj4" target="_blank">press release</a> went out a few hours ago, and the launch webcast just finished minutes ago, announcing the arrival of <strong>Oracle Identity Management 11g</strong>, the next phase in our rollout of the most complete, integrated and open suite of identity management products. As Amit Jasuja shared in the webcast, there is over 750 man months of development and 1300 man months of QA in this release, which is built on a common platform of shared identity services and is optimized to support the evolving needs of the modern enterprise. The key design themes that drove our work over the last 3+ years were: Service-Oriented Security, suite-wide integration and standardization of the products, and support for heterogeneous environments.</p>
<p><img class="alignnone size-full wp-image-962" title="IdM11gDesignThemes" src="http://blog.talkingidentity.com/wp-content/uploads/2010/07/IdM11gDesignThemes.jpg" alt="IdM11gDesignThemes" width="550" height="292" /></p>
<p>In a <a href="http://bit.ly/91jMgP" target="_self">previous post</a>, I described which IdM products were included in the first rollout of 11g last year. This phase includes the following products:</p>
<ul>
<li>Oracle Identity Manager</li>
<li>Oracle Identity Analytics</li>
<li>Oracle Access Manager</li>
<li>Oracle Adaptive Access Manager</li>
<li>Oracle Directory Server Enterprise Edition</li>
<li>Oracle OpenSSO Secure Token Service</li>
<li>Oracle OpenSSO Fedlet</li>
<li>Oracle Navigator</li>
<li>Oracle Enterprise Manager Grid Control Pack for IdM</li>
</ul>
<p>As you can see, a major focus of this release (and a late add to the slate, I might add) was delivering on some of the promises we made to integrate the Sun IdM products into our portfolio. The other was to address customer concerns around manageability and usability of the products. If you saw the webcast, you saw the demos showing off the slick new desktop-like UI that the products are sporting, based on Oracle ADF. The shared services model removes inconsistencies between the different products in the suite, both from a behavior and functionality standpoint. And a lot of attention was paid to really ratcheting up performance to meet enterprise needs as they start to manage extranet environments in addition to their intranet environments.</p>
<p>In the coming weeks I and other bloggers in the Oracle IdM community will share a lot more detail about these releases. So stay tuned. In the meantime, check out the <a href="http://bit.ly/cZjBc1" target="_blank">Fusion Middleware Launch Center</a>, w<span><span><span>here you&#8217;ll find videos, data sheets, webinar&#8217;s, and white papers</span></span></span></p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/oracle-identity-management" rel="tag">Oracle Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/oracle-identity-management-11g" rel="tag">Oracle Identity Management 11g</a>, <a href="http://blog.talkingidentity.com/tag/service-oriented-security" rel="tag">Service-Oriented Security</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DAnnouncing%2520Oracle%2520Identity%2520Management%252011g%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fannouncing-oracle-identity-management-11g.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fannouncing-oracle-identity-management-11g.html%26amp%3Btitle%3DAnnouncing%2520Oracle%2520Identity%2520Management%252011g%26amp%3Bbodytext%3DWell%252C%2520the%2520press%2520release%2520went%2520out%2520a%2520few%2520hours%2520ago%252C%2520and%2520the%2520launch%2520webcast%2520just%2520finished%2520minutes%2520ago%252C%2520announcing%2520the%2520arrival%2520of%2520Oracle%2520Identity%2520Management%252011g%252C%2520the%2520next%2520phase%2520in%2520our%2520rollout%2520of%2520the%2520most%2520complete%252C%2520integrated%2520and%2520open%2520suite%2520of%2520identity%2520ma';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fannouncing-oracle-identity-management-11g.html%26amp%3Bt%3DAnnouncing%2520Oracle%2520Identity%2520Management%252011g';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fannouncing-oracle-identity-management-11g.html%26amp%3Btitle%3DAnnouncing%2520Oracle%2520Identity%2520Management%252011g';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fannouncing-oracle-identity-management-11g.html%26amp%3Btitle%3DAnnouncing%2520Oracle%2520Identity%2520Management%252011g%26amp%3Bannotation%3DWell%252C%2520the%2520press%2520release%2520went%2520out%2520a%2520few%2520hours%2520ago%252C%2520and%2520the%2520launch%2520webcast%2520just%2520finished%2520minutes%2520ago%252C%2520announcing%2520the%2520arrival%2520of%2520Oracle%2520Identity%2520Management%252011g%252C%2520the%2520next%2520phase%2520in%2520our%2520rollout%2520of%2520the%2520most%2520complete%252C%2520integrated%2520and%2520open%2520suite%2520of%2520identity%2520ma';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fannouncing-oracle-identity-management-11g.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fannouncing-oracle-identity-management-11g.html%26amp%3Btitle%3DAnnouncing%2520Oracle%2520Identity%2520Management%252011g%26amp%3Bnotes%3DWell%252C%2520the%2520press%2520release%2520went%2520out%2520a%2520few%2520hours%2520ago%252C%2520and%2520the%2520launch%2520webcast%2520just%2520finished%2520minutes%2520ago%252C%2520announcing%2520the%2520arrival%2520of%2520Oracle%2520Identity%2520Management%252011g%252C%2520the%2520next%2520phase%2520in%2520our%2520rollout%2520of%2520the%2520most%2520complete%252C%2520integrated%2520and%2520open%2520suite%2520of%2520identity%2520ma';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fannouncing-oracle-identity-management-11g.html%26amp%3Btitle%3DAnnouncing%2520Oracle%2520Identity%2520Management%252011g';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fannouncing-oracle-identity-management-11g.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fannouncing-oracle-identity-management-11g.html%26amp%3Bh%3DAnnouncing%2520Oracle%2520Identity%2520Management%252011g';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DAnnouncing%2520Oracle%2520Identity%2520Management%252011g%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fannouncing-oracle-identity-management-11g.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fannouncing-oracle-identity-management-11g.html%2520Announcing%2520Oracle%2520Identity%2520Management%252011g';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DAnnouncing%2520Oracle%2520Identity%2520Management%252011g%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fannouncing-oracle-identity-management-11g.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/07/announcing-oracle-identity-management-11g.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>It&#8217;s All in the Cooking &#8211; 11g Drops Today</title>
		<link>http://blog.talkingidentity.com/2010/07/its-all-in-the-cooking-11g-drops-today.html</link>
		<comments>http://blog.talkingidentity.com/2010/07/its-all-in-the-cooking-11g-drops-today.html#comments</comments>
		<pubDate>Wed, 21 Jul 2010 12:50:46 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[Oracle Identity Management 11g]]></category>
		<category><![CDATA[Service-Oriented Security]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=955</guid>
		<description><![CDATA[Last week I was at Oracle HQ for our annual Identity Management Customer Advisory Board meeting. It was an absolutely jam-packed two and a half days. I cannot tell you how great it was to spend time with our customers, those that have been with us for a while, and those that just joined the [...]]]></description>
			<content:encoded><![CDATA[<p>Last week I was at Oracle HQ for our annual Identity Management Customer Advisory Board meeting. <img class="alignright" title="Expert Cheese Grating" src="http://farm5.static.flickr.com/4116/4814763628_fafc528e4b_m.jpg" alt="" width="141" height="240" />It was an absolutely jam-packed two and a half days. I cannot tell you how great it was to spend time with our customers, those that have been with us for a while, and those that just joined the CAB via the Sun acquisition. We had some great customer presentations as they shared insight with the group and threw out some meaty topics for us to chew on. Some of our customers are doing some really innovative things, and I am hoping to be able to share some of that with you in upcoming posts (once I get clearance). I gave a talk on our plans as they relate to SaaS applications and the Cloud, and I&#8217;m quite pleased with the positive feedback I&#8217;ve been getting. And the Iron Chef competition at the Payne Mansion was a rousing success, despite the team I was on coming in last (I did establish myself as a champion cheese grater though).</p>
<p>But the best part of the CAB was the response that our customers gave us for the upcoming Oracle Identity Management 11g release. No one is in a better position to judge whether we are delivering on what our customers need than the organizations that have been using our products for years now. We got positive affirmation that makes me believe that the focus we put on usability, manageability, identity services architecture and suite integration is going to pay off. The demo sessions were packed and warmly received, even running long because of all the discussions that ensued. And you know you did a good job when customers start to come up with new ideas that play off your new features instead of critiquing those features themselves.</p>
<p>Well, today is launch day, and finally the entire identity industry can see what we have been cooking and judge for themselves. To get started, you can check out <a href="http://bit.ly/csdy72" target="_blank">the launch webcast today</a> (Wednesday, July 21) at 10:00 a.m. PT / 1:00 p.m. ET. Our VP for development of Identity Management products, Amit Jasuja, will be providing a detailed introduction to this release, so <a href="http://bit.ly/csdy72" target="_blank">register now</a>. There will be a whole bunch of information being put up on oracle.com/identity. And if you are going to be at Burton Catalyst in San Diego next week, then you can stop by the Oracle hospitality suite (Wednesday, July 28 from 6-9 pm in room Aqua 308) and see demos of all the new products.</p>
<p><a href="http://bit.ly/csdy72" target="_blank"><img class="alignnone size-full wp-image-939" title="IdM 11g Webcast" src="http://blog.talkingidentity.com/wp-content/uploads/2010/07/IdM-11g-Webcast.jpg" alt="IdM 11g Webcast" width="550" height="158" /></a></p>
<p>I can assure you that we build IdM products much better than we cook miniature ham croquettes minus the ham (you had to be there).</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/oracle-identity-management" rel="tag">Oracle Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/oracle-identity-management-11g" rel="tag">Oracle Identity Management 11g</a>, <a href="http://blog.talkingidentity.com/tag/service-oriented-security" rel="tag">Service-Oriented Security</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DIt%2527s%2520All%2520in%2520the%2520Cooking%2520-%252011g%2520Drops%2520Today%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fits-all-in-the-cooking-11g-drops-today.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fits-all-in-the-cooking-11g-drops-today.html%26amp%3Btitle%3DIt%2527s%2520All%2520in%2520the%2520Cooking%2520-%252011g%2520Drops%2520Today%26amp%3Bbodytext%3DLast%2520week%2520I%2520was%2520at%2520Oracle%2520HQ%2520for%2520our%2520annual%2520Identity%2520Management%2520Customer%2520Advisory%2520Board%2520meeting.%2520It%2520was%2520an%2520absolutely%2520jam-packed%2520two%2520and%2520a%2520half%2520days.%2520I%2520cannot%2520tell%2520you%2520how%2520great%2520it%2520was%2520to%2520spend%2520time%2520with%2520our%2520customers%252C%2520those%2520that%2520have%2520been%2520with%2520us%2520fo';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fits-all-in-the-cooking-11g-drops-today.html%26amp%3Bt%3DIt%2527s%2520All%2520in%2520the%2520Cooking%2520-%252011g%2520Drops%2520Today';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fits-all-in-the-cooking-11g-drops-today.html%26amp%3Btitle%3DIt%2527s%2520All%2520in%2520the%2520Cooking%2520-%252011g%2520Drops%2520Today';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fits-all-in-the-cooking-11g-drops-today.html%26amp%3Btitle%3DIt%2527s%2520All%2520in%2520the%2520Cooking%2520-%252011g%2520Drops%2520Today%26amp%3Bannotation%3DLast%2520week%2520I%2520was%2520at%2520Oracle%2520HQ%2520for%2520our%2520annual%2520Identity%2520Management%2520Customer%2520Advisory%2520Board%2520meeting.%2520It%2520was%2520an%2520absolutely%2520jam-packed%2520two%2520and%2520a%2520half%2520days.%2520I%2520cannot%2520tell%2520you%2520how%2520great%2520it%2520was%2520to%2520spend%2520time%2520with%2520our%2520customers%252C%2520those%2520that%2520have%2520been%2520with%2520us%2520fo';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fits-all-in-the-cooking-11g-drops-today.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fits-all-in-the-cooking-11g-drops-today.html%26amp%3Btitle%3DIt%2527s%2520All%2520in%2520the%2520Cooking%2520-%252011g%2520Drops%2520Today%26amp%3Bnotes%3DLast%2520week%2520I%2520was%2520at%2520Oracle%2520HQ%2520for%2520our%2520annual%2520Identity%2520Management%2520Customer%2520Advisory%2520Board%2520meeting.%2520It%2520was%2520an%2520absolutely%2520jam-packed%2520two%2520and%2520a%2520half%2520days.%2520I%2520cannot%2520tell%2520you%2520how%2520great%2520it%2520was%2520to%2520spend%2520time%2520with%2520our%2520customers%252C%2520those%2520that%2520have%2520been%2520with%2520us%2520fo';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fits-all-in-the-cooking-11g-drops-today.html%26amp%3Btitle%3DIt%2527s%2520All%2520in%2520the%2520Cooking%2520-%252011g%2520Drops%2520Today';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fits-all-in-the-cooking-11g-drops-today.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fits-all-in-the-cooking-11g-drops-today.html%26amp%3Bh%3DIt%2527s%2520All%2520in%2520the%2520Cooking%2520-%252011g%2520Drops%2520Today';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DIt%2527s%2520All%2520in%2520the%2520Cooking%2520-%252011g%2520Drops%2520Today%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fits-all-in-the-cooking-11g-drops-today.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fits-all-in-the-cooking-11g-drops-today.html%2520It%2527s%2520All%2520in%2520the%2520Cooking%2520-%252011g%2520Drops%2520Today';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DIt%2527s%2520All%2520in%2520the%2520Cooking%2520-%252011g%2520Drops%2520Today%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F07%252Fits-all-in-the-cooking-11g-drops-today.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/07/its-all-in-the-cooking-11g-drops-today.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
