<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Talking Identity &#187; Cloud Identity Model</title>
	<atom:link href="http://blog.talkingidentity.com/tag/cloud-identity-model/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.talkingidentity.com</link>
	<description>An Architect's Quest to make sense of the world of Identity and Access Management</description>
	<lastBuildDate>Sat, 06 Mar 2010 03:32:56 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Can OAuth do what SPML hasn&#8217;t?</title>
		<link>http://blog.talkingidentity.com/2009/11/can-oauth-do-what-spml-hasnt.html</link>
		<comments>http://blog.talkingidentity.com/2009/11/can-oauth-do-what-spml-hasnt.html#comments</comments>
		<pubDate>Tue, 24 Nov 2009 21:52:03 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[The Cloud Identity Series]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cloud Identity Model]]></category>
		<category><![CDATA[Federated Provisioning]]></category>
		<category><![CDATA[OAuth]]></category>
		<category><![CDATA[SPML]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=720</guid>
		<description><![CDATA[I spent an interesting week at HQ last week, trying to deal with some of the craziness that occurs every time a major release is on its way. But far more interesting were all the identity management conversations I engaged in during the course of the week &#8211; in hallways, over meals and especially over [...]]]></description>
			<content:encoded><![CDATA[<p>I spent an interesting week at HQ last week, trying to deal with some of the craziness that occurs every time a major release is on its way. But far more interesting were all the identity management conversations I engaged in during the course of the week &#8211; in hallways, over meals and especially over drinks. Suffice to say that it was a very thought provoking week. I wanted to use this forum to expand on a conversation that started in one venue, and then spilled over into the Twitterverse.</p>
<p>One of the topics that has been fodder for some animated discussion has been the <a href="http://blog.talkingidentity.com/tag/federated-provisioning" target="_blank">topic of federated provisioning</a>. As the cloud has brought federated authentication back into focus, it has also shone a light on the need for federated provisioning to power cloud identity. After a very interesting discussion that I had with some folks who are looking at identity in the cloud, <a href="http://twitter.com/NishantK/status/5806488992" target="_blank">I posed the following question</a> on Twitter:</p>
<blockquote><p>Had an interesting discussion this morning on how OAuth could be to federated provisioning what OpenID is to federated SSO. Any takers?</p></blockquote>
<h3>The Thesis</h3>
<p>Federated provisioning is about creating an account with appropriate privileges in underlying systems on the <em>Relying Party</em> side when triggered by an authentication event (user comes to the <em>RP</em> service from the <em>Identity Provider</em>, or <em>IdP</em>, side). Further, the authentication token being presented to the <em>RP</em> does not contain sufficient claims (attributes, etc) for the systems on the <em>RP</em> side to create the necessary account (there are other scenarios, of course, but this is the common one I am trying to address). Consequently, we have a need for the <em>RP</em> to get provisioned with data from the <em>IdP</em> side.</p>
<p>Now in my post &#8220;<a href="http://blog.talkingidentity.com/2009/02/the_thing_about_federated_prov.html" target="_blank">The Thing About Federated Provisioning</a>&#8220;, I pointed out that there are challenges in doing all of this just-in-time. Enterprises often resort to out-of-band pre-provisioning of accounts across the domain boundaries, which is where SPML proves to be adequate. But the demand for JIT mechanisms still exists. The cloud exacerbates this problem greatly, because pre-provisioning is pretty much impossible when you move up to the scale and loose coupling of the cloud. And the nature of SPML requires that extensive integration be done before the connection between the RP and the IdP can go live.</p>
<p><a href="http://oauth.net/"><img class="alignright" title="OAuth" src="http://hueniverse.com/wp-content/uploads/2009/09/OAuth-Shine-300x298.png" alt="" width="193" height="191" /></a>And this is where I believe <strong>OAuth</strong> could play a role. OpenID is already viewed as a lightweight solution for enabling federated authentication, with attribute exchange supporting the simpler data transport scenarios. We could now augment this flow by adding an <em>OAuth-based data provisioning</em> mechanism that allows a <em>Provisioning Service </em>on the <em>RP</em> side to connect back to a <em>Provisioning Service </em>on the <em>IdP</em> side and retrieve the data it needs to create the underlying accounts. Being based on OAuth, this would require far less integration than the SPML based approach would.</p>
<p>Mapping the concepts, the <em>RPs Provisioning Service</em> becomes the <em>OAuth Consumer</em>, while the <em>IdPs Provisioning Service</em> becomes the <em>OAuth Service Provider</em>. The interactions are outlined in the diagram below (greatly simplified for the purposes of this discussion).</p>
<p><img class="aligncenter size-full wp-image-726" title="OAuth for Fed-Prov" src="http://blog.talkingidentity.com/wp-content/uploads/2009/11/OAuth-for-Fed-Prov.jpg" alt="OAuth for Fed-Prov" width="500" height="312" /></p>
<h3>The Challenge</h3>
<p>But when you look at the actors involved in OAuth, you run into one problem &#8211; OAuth was defined with users in mind, not enterprises. So you find the User as part of the protocol, but nothing that would allow the Enterprise to have a say in the exchange. And this raises an interesting challenge.</p>
<p>Just like there are security issues to resolve in the OpenID protocol for it to satisfy enterprise requirements, there are policy challenges that would need to be resolved in the OAuth exchange as well. Connecting the services only requires that the user in the flow provide their assent, but if OAuth were to step in as a federated provisioning protocol, it would require some way for the enterprise to inject (fine-grained) business policy into the exchange. And what if approval workflow needs to enter the picture?</p>
<p>One thought would be to introduce an <a href="http://www.openliberty.org/wiki/index.php/IGF_Introduction" target="_blank">IGF</a> style declarative policy mechanism that would allow the services on each side of the exchange to declare intent and policy, thereby allowing some automated decision making that ensures that security and business policies are honored by the exchange. Because when you are talking about fed-prov, a one-size-fits-all construct will be a non-starter.</p>
<p>My posting on twitter did generate some good feedback from folks like <a href="http://twitter.com/xmlgrrl" target="_blank">Eve Maler</a> and <a href="http://twitter.com/itickr" target="_blank">Ashish Jain</a>. I am interested to get people&#8217;s thoughts on the viability of this idea, and whether you think adding OAuth to provisioning systems would be part of the move to enabling enterprise identity management systems for the cloud.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/cloud-computing" rel="tag">Cloud Computing</a>, <a href="http://blog.talkingidentity.com/tag/cloud-identity-model" rel="tag">Cloud Identity Model</a>, <a href="http://blog.talkingidentity.com/tag/federated-provisioning" rel="tag">Federated Provisioning</a>, <a href="http://blog.talkingidentity.com/tag/oauth" rel="tag">OAuth</a>, <a href="http://blog.talkingidentity.com/tag/spml" rel="tag">SPML</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DCan%2520OAuth%2520do%2520what%2520SPML%2520hasn%2527t%253F%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2009%252F11%252Fcan-oauth-do-what-spml-hasnt.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F11%252Fcan-oauth-do-what-spml-hasnt.html%26amp%3Btitle%3DCan%2520OAuth%2520do%2520what%2520SPML%2520hasn%2527t%253F%26amp%3Bbodytext%3DI%2520spent%2520an%2520interesting%2520week%2520at%2520HQ%2520last%2520week%252C%2520trying%2520to%2520deal%2520with%2520some%2520of%2520the%2520craziness%2520that%2520occurs%2520every%2520time%2520a%2520major%2520release%2520is%2520on%2520its%2520way.%2520But%2520far%2520more%2520interesting%2520were%2520all%2520the%2520identity%2520management%2520conversations%2520I%2520engaged%2520in%2520during%2520the%2520course%2520of%2520the';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F11%252Fcan-oauth-do-what-spml-hasnt.html%26amp%3Bt%3DCan%2520OAuth%2520do%2520what%2520SPML%2520hasn%2527t%253F';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" id="linkedin" href="javascript:window.location='http%3A%2F%2Fwww.linkedin.com%2FshareArticle%3Fmini%3Dtrue%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F11%252Fcan-oauth-do-what-spml-hasnt.html%26amp%3Btitle%3DCan%2520OAuth%2520do%2520what%2520SPML%2520hasn%2527t%253F%26amp%3Bsource%3DTalking%2BIdentity%2BAn%2BArchitect%2527s%2BQuest%2Bto%2Bmake%2Bsense%2Bof%2Bthe%2Bworld%2Bof%2BIdentity%2Band%2BAccess%2BManagement%26amp%3Bsummary%3DI%2520spent%2520an%2520interesting%2520week%2520at%2520HQ%2520last%2520week%252C%2520trying%2520to%2520deal%2520with%2520some%2520of%2520the%2520craziness%2520that%2520occurs%2520every%2520time%2520a%2520major%2520release%2520is%2520on%2520its%2520way.%2520But%2520far%2520more%2520interesting%2520were%2520all%2520the%2520identity%2520management%2520conversations%2520I%2520engaged%2520in%2520during%2520the%2520course%2520of%2520the';" title="LinkedIn"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F11%252Fcan-oauth-do-what-spml-hasnt.html%26amp%3Btitle%3DCan%2520OAuth%2520do%2520what%2520SPML%2520hasn%2527t%253F';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F11%252Fcan-oauth-do-what-spml-hasnt.html%26amp%3Btitle%3DCan%2520OAuth%2520do%2520what%2520SPML%2520hasn%2527t%253F%26amp%3Bannotation%3DI%2520spent%2520an%2520interesting%2520week%2520at%2520HQ%2520last%2520week%252C%2520trying%2520to%2520deal%2520with%2520some%2520of%2520the%2520craziness%2520that%2520occurs%2520every%2520time%2520a%2520major%2520release%2520is%2520on%2520its%2520way.%2520But%2520far%2520more%2520interesting%2520were%2520all%2520the%2520identity%2520management%2520conversations%2520I%2520engaged%2520in%2520during%2520the%2520course%2520of%2520the';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F11%252Fcan-oauth-do-what-spml-hasnt.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F11%252Fcan-oauth-do-what-spml-hasnt.html%26amp%3Btitle%3DCan%2520OAuth%2520do%2520what%2520SPML%2520hasn%2527t%253F%26amp%3Bnotes%3DI%2520spent%2520an%2520interesting%2520week%2520at%2520HQ%2520last%2520week%252C%2520trying%2520to%2520deal%2520with%2520some%2520of%2520the%2520craziness%2520that%2520occurs%2520every%2520time%2520a%2520major%2520release%2520is%2520on%2520its%2520way.%2520But%2520far%2520more%2520interesting%2520were%2520all%2520the%2520identity%2520management%2520conversations%2520I%2520engaged%2520in%2520during%2520the%2520course%2520of%2520the';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F11%252Fcan-oauth-do-what-spml-hasnt.html%26amp%3Btitle%3DCan%2520OAuth%2520do%2520what%2520SPML%2520hasn%2527t%253F';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F11%252Fcan-oauth-do-what-spml-hasnt.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F11%252Fcan-oauth-do-what-spml-hasnt.html%26amp%3Bh%3DCan%2520OAuth%2520do%2520what%2520SPML%2520hasn%2527t%253F';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DCan%2520OAuth%2520do%2520what%2520SPML%2520hasn%2527t%253F%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F11%252Fcan-oauth-do-what-spml-hasnt.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2009%252F11%252Fcan-oauth-do-what-spml-hasnt.html%2520Can%2520OAuth%2520do%2520what%2520SPML%2520hasn%2527t%253F';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DCan%2520OAuth%2520do%2520what%2520SPML%2520hasn%2527t%253F%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F11%252Fcan-oauth-do-what-spml-hasnt.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2009/11/can-oauth-do-what-spml-hasnt.html/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Screencast of my OpenWorld Session on &#8220;IdM and the Cloud&#8221;</title>
		<link>http://blog.talkingidentity.com/2009/10/screencast-of-my-openworld-session-on-idm-and-the-cloud.html</link>
		<comments>http://blog.talkingidentity.com/2009/10/screencast-of-my-openworld-session-on-idm-and-the-cloud.html#comments</comments>
		<pubDate>Fri, 16 Oct 2009 19:20:21 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Identity Services]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cloud Identity Model]]></category>
		<category><![CDATA[OOW09]]></category>
		<category><![CDATA[Oracle OpenWorld]]></category>
		<category><![CDATA[Oracle_IDM]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=682</guid>
		<description><![CDATA[On Monday, I presented at Oracle OpenWorld on the topic of &#8220;Identity Management and the Cloud: Stormy Days Ahead?&#8220;. The title proved to be a little too prescient, because the weather in San Francisco was pretty nasty. And as you can imagine, the number of jokes made about this became all to predictable.
Unfortunate coincidences on [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.oracle.com/us/openworld/index.htm"><img class="alignright" title="Oracle OpenWorld 2009" src="http://oracleimg.com/admin/images/oow09/ocom_oowsf09_reg_banner.gif" alt="" width="185" height="125" /></a>On Monday, I presented at Oracle OpenWorld on the topic of &#8220;<strong>Identity Management and the Cloud: Stormy Days Ahead?</strong>&#8220;. The title proved to be a little too prescient, because the weather in San Francisco was pretty nasty. And as you can imagine, the number of jokes made about this became all to predictable.</p>
<p>Unfortunate coincidences on the title aside, the overall response to my session was quite positive, especially from folks whose opinions I really respect like <a href="http://bit.ly/3iVPOq" target="_blank">Bob Blakley</a> and Lori Rowland from the Burton Group. There was general agreement that widespread adoption of Cloud Computing is going to be a major disruption on the existing evolutionary path that Identity Management has been following. And adoption of the Identity Services model is a major component to readying IdM for the Cloud.</p>
<p>Check out the screencast (slides with audio of the session) of my session below. Registered attendees of OpenWorld can download the presentation itself and the MP3 audio recording of the session from <a href="http://bit.ly/1OgIvs" target="_blank">OpenWorld On-Demand</a> (just login with the Username and Password you created during your OOW registration).</p>
<div id="__ss_2222693" style="width: 425px; text-align: left;"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" title="IdM And The Cloud: Stormy Days Ahead?" href="http://bit.ly/bRO1u">IdM And The Cloud: Stormy Days Ahead?</a><object style="margin:0px" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="355" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=s309525-idmandthecloudstormydaysahead-091014121834-phpapp02&amp;rel=0&amp;stripped_title=idm-and-the-cloud-stormy-days-ahead" /><param name="allowfullscreen" value="true" /><embed style="margin:0px" type="application/x-shockwave-flash" width="425" height="355" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=s309525-idmandthecloudstormydaysahead-091014121834-phpapp02&amp;rel=0&amp;stripped_title=idm-and-the-cloud-stormy-days-ahead" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<div style="font-size: 11px; font-family: tahoma,arial; height: 26px; padding-top: 2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://bit.ly/eYtlC">Nishant Kaushik</a>.</div>
</div>
<p>The audio includes the questions that were asked of me, and turns out that the questions didn&#8217;t record well and I forgot to repeat them. Hopefully my answers are cogent enough that you get an idea of what questions were asked. I did want to follow up here on this blog post a few of those answers:</p>
<ul>
<li>A question came up regarding the licensing terms for Oracle IdM products when they are being used in a cloud environment (specifically, by organizations that are going to be Cloud Providers of Identity Services). The biggest challenge for such organizations is that they cannot accurately estimate the number of users, or other such variables licensing is typically based on, beforehand, which creates uncertainty for them as to the cost they will have to bear. After the session, I confirmed with our PM team that there is special licensing available for ISVs. Talk to your Oracle sales rep about this if interested.</li>
<li>Another question came up regarding the impact of all this on standards like SPML. I believe my answer covered my opinion on the greater emphasis the cloud identity model will put on the evolution of these standards, especially SPML, which has been languishing. Follow up conversations with some of the original architects of the SPML standard and others involved in standards efforts brought up that the communities responsible for these standards are looking at this very hard and are gearing up efforts to address this. So stay tuned for more on that.</li>
<li>A question was asked regarding Just-In-Time Deprovisioning of access to cloud-based assets. This is something <a href="http://bit.ly/4lX6Wr">I discussed quite a bit in a blog conversation</a> with folks like <a href="http://www.tuesdaynight.org/2009/02/05/will-the-real-federated-provisioning-please-stand-up.html">Ian Glazer</a> and <a href="http://eternallyoptimistic.com/2009/02/05/federated-de-provisioning/">Pam Dingle</a> a while back. So check out that <a href="http://bit.ly/4lX6Wr">post</a> and the related thread.</li>
</ul>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/cloud-computing" rel="tag">Cloud Computing</a>, <a href="http://blog.talkingidentity.com/tag/cloud-identity-model" rel="tag">Cloud Identity Model</a>, <a href="http://blog.talkingidentity.com/tag/identity-services" rel="tag">Identity Services</a>, <a href="http://blog.talkingidentity.com/tag/oow09" rel="tag">OOW09</a>, <a href="http://blog.talkingidentity.com/tag/oracle-openworld" rel="tag">Oracle OpenWorld</a>, <a href="http://blog.talkingidentity.com/tag/oracle_idm" rel="tag">Oracle_IDM</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DScreencast%2520of%2520my%2520OpenWorld%2520Session%2520on%2520%2522IdM%2520and%2520the%2520Cloud%2522%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fscreencast-of-my-openworld-session-on-idm-and-the-cloud.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fscreencast-of-my-openworld-session-on-idm-and-the-cloud.html%26amp%3Btitle%3DScreencast%2520of%2520my%2520OpenWorld%2520Session%2520on%2520%2522IdM%2520and%2520the%2520Cloud%2522%26amp%3Bbodytext%3DOn%2520Monday%252C%2520I%2520presented%2520at%2520Oracle%2520OpenWorld%2520on%2520the%2520topic%2520of%2520%2522Identity%2520Management%2520and%2520the%2520Cloud%253A%2520Stormy%2520Days%2520Ahead%253F%2522.%2520The%2520title%2520proved%2520to%2520be%2520a%2520little%2520too%2520prescient%252C%2520because%2520the%2520weather%2520in%2520San%2520Francisco%2520was%2520pretty%2520nasty.%2520And%2520as%2520you%2520can%2520imagine%252C%2520the%2520numb';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fscreencast-of-my-openworld-session-on-idm-and-the-cloud.html%26amp%3Bt%3DScreencast%2520of%2520my%2520OpenWorld%2520Session%2520on%2520%2522IdM%2520and%2520the%2520Cloud%2522';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" id="linkedin" href="javascript:window.location='http%3A%2F%2Fwww.linkedin.com%2FshareArticle%3Fmini%3Dtrue%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fscreencast-of-my-openworld-session-on-idm-and-the-cloud.html%26amp%3Btitle%3DScreencast%2520of%2520my%2520OpenWorld%2520Session%2520on%2520%2522IdM%2520and%2520the%2520Cloud%2522%26amp%3Bsource%3DTalking%2BIdentity%2BAn%2BArchitect%2527s%2BQuest%2Bto%2Bmake%2Bsense%2Bof%2Bthe%2Bworld%2Bof%2BIdentity%2Band%2BAccess%2BManagement%26amp%3Bsummary%3DOn%2520Monday%252C%2520I%2520presented%2520at%2520Oracle%2520OpenWorld%2520on%2520the%2520topic%2520of%2520%2522Identity%2520Management%2520and%2520the%2520Cloud%253A%2520Stormy%2520Days%2520Ahead%253F%2522.%2520The%2520title%2520proved%2520to%2520be%2520a%2520little%2520too%2520prescient%252C%2520because%2520the%2520weather%2520in%2520San%2520Francisco%2520was%2520pretty%2520nasty.%2520And%2520as%2520you%2520can%2520imagine%252C%2520the%2520numb';" title="LinkedIn"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fscreencast-of-my-openworld-session-on-idm-and-the-cloud.html%26amp%3Btitle%3DScreencast%2520of%2520my%2520OpenWorld%2520Session%2520on%2520%2522IdM%2520and%2520the%2520Cloud%2522';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fscreencast-of-my-openworld-session-on-idm-and-the-cloud.html%26amp%3Btitle%3DScreencast%2520of%2520my%2520OpenWorld%2520Session%2520on%2520%2522IdM%2520and%2520the%2520Cloud%2522%26amp%3Bannotation%3DOn%2520Monday%252C%2520I%2520presented%2520at%2520Oracle%2520OpenWorld%2520on%2520the%2520topic%2520of%2520%2522Identity%2520Management%2520and%2520the%2520Cloud%253A%2520Stormy%2520Days%2520Ahead%253F%2522.%2520The%2520title%2520proved%2520to%2520be%2520a%2520little%2520too%2520prescient%252C%2520because%2520the%2520weather%2520in%2520San%2520Francisco%2520was%2520pretty%2520nasty.%2520And%2520as%2520you%2520can%2520imagine%252C%2520the%2520numb';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fscreencast-of-my-openworld-session-on-idm-and-the-cloud.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fscreencast-of-my-openworld-session-on-idm-and-the-cloud.html%26amp%3Btitle%3DScreencast%2520of%2520my%2520OpenWorld%2520Session%2520on%2520%2522IdM%2520and%2520the%2520Cloud%2522%26amp%3Bnotes%3DOn%2520Monday%252C%2520I%2520presented%2520at%2520Oracle%2520OpenWorld%2520on%2520the%2520topic%2520of%2520%2522Identity%2520Management%2520and%2520the%2520Cloud%253A%2520Stormy%2520Days%2520Ahead%253F%2522.%2520The%2520title%2520proved%2520to%2520be%2520a%2520little%2520too%2520prescient%252C%2520because%2520the%2520weather%2520in%2520San%2520Francisco%2520was%2520pretty%2520nasty.%2520And%2520as%2520you%2520can%2520imagine%252C%2520the%2520numb';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fscreencast-of-my-openworld-session-on-idm-and-the-cloud.html%26amp%3Btitle%3DScreencast%2520of%2520my%2520OpenWorld%2520Session%2520on%2520%2522IdM%2520and%2520the%2520Cloud%2522';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fscreencast-of-my-openworld-session-on-idm-and-the-cloud.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fscreencast-of-my-openworld-session-on-idm-and-the-cloud.html%26amp%3Bh%3DScreencast%2520of%2520my%2520OpenWorld%2520Session%2520on%2520%2522IdM%2520and%2520the%2520Cloud%2522';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DScreencast%2520of%2520my%2520OpenWorld%2520Session%2520on%2520%2522IdM%2520and%2520the%2520Cloud%2522%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fscreencast-of-my-openworld-session-on-idm-and-the-cloud.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fscreencast-of-my-openworld-session-on-idm-and-the-cloud.html%2520Screencast%2520of%2520my%2520OpenWorld%2520Session%2520on%2520%2522IdM%2520and%2520the%2520Cloud%2522';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DScreencast%2520of%2520my%2520OpenWorld%2520Session%2520on%2520%2522IdM%2520and%2520the%2520Cloud%2522%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fscreencast-of-my-openworld-session-on-idm-and-the-cloud.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2009/10/screencast-of-my-openworld-session-on-idm-and-the-cloud.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
