Welcome!

Microservices Expo Authors: Liz McMillan, Pat Romanski, Elizabeth White, Stackify Blog, Andreas Grabner

Related Topics: Microservices Expo

Microservices Expo: Article

Identity CrisisPassport may not fill the need for a global identity service

Identity CrisisPassport may not fill the need for a global identity service

Do you have a .NET Passport identity? You may not realize it, but chances are reasonably high that you do. If you have a HotMail or MSN account, Microsoft assigned a Passport identity to you automatically. Microsoft claims to have more than 160 million users registered in the Passport identity service.

Pretty soon you'll need a Passport ID to have any interaction with Microsoft. In December 2001, quite a few gamesters were surprised to discover that their old accounts at the Microsoft Zone gaming site wouldn't work without a Passport ID. Microsoft also requires a Passport ID to join MSDN, to register for a Microsoft seminar, or to access Microsoft's node in the UDDI public registry. The new Windows XP Product Activation (WPA) system uses Passport by default. You can also use your Passport ID to log in to your XP system.

So just what does a Passport identity do for you? Obviously, it lets Microsoft track your activities, but that's not a particularly strong incentive for most users. Most consumers view Passport as an electronic wallet. You can associate a credit card with your Passport ID and use it to buy things at any site that supports Passport Express Purchase. This sounds pretty useful, except that Microsoft hasn't been especially successful in recruiting e-tailers to support Passport (there are less than 100 participating sites so far). Even so, Passport can fill in Web forms for you, alleviating the need to type in your name and address at every site.

But Passport has a much more useful role to play in the future, particularly in the realm of Web services. Passport provides a cross-corporate single-signon service, which is critical to allow Web services to work together.

Today most Web services work alone, but in the future we want to be able to assemble multiple Web services to create more powerful business services. First we need to provide a way to let Web services share information.

Consider how most Web services implement security today. Each business that offers a secure Web service maintains a list of authorized users, who authenticate themselves using a userid and password. When we start assembling Web services, we don't want to force the user to type in a userid and password for every Web service involved in the aggregate business service, and we don't want to force Web service providers to develop point-to-point security connections for each Web service assembly effort. Instead, we need a facility that enables single sign-on across any number of Web services operated by any number of businesses. What we need is a global identity service.

Passport could be used as a global identity service but there is one serious impediment. Passport isn't open. Microsoft intends to collect revenue from businesses that use Passport for authentication. While I will grant that Microsoft has the right to make money from its innovations, I suspect that not every business wants to pay Microsoft to manage its authentication process. And many businesses won't be inclined to let Microsoft own their customer information. Hence, I doubt that Passport will ever become the de facto global identity service.

In September Microsoft announced plans to "open up" Passport by adding support for Kerberos V5, but this feature still won't make Passport open. What it means is that Passport will be able to access your internal user management system (such as Active Directory) to retrieve user identity information, assuming, of course, that it supports Kerberos V5.0. (I probably don't need to tell you that Active Directory supports Kerberos V5.0.) Keep in mind that although you would be managing and maintaining your own list of authorized users, all identity and authentication requests still need to go through Microsoft's Passport service, allowing Microsoft to collect a toll.

It would be a lot better if there were standards associated with Identity that would allow anyone to set up an Identity Service so that any Web service could authenticate users using any Identity Service. This approach would allow users a wide choice of Identity options. Personally, I'd feel much more comfortable giving control of my financial information to my bank than to Microsoft.

Standards for Identity would include an XML format that represents user information and an API that is used to access any compliant Identity Service. The Liberty Alliance Project, which is working to define Identity standards, says it intends "to create an open, federated solution for network identity - enabling ubiquitous single sign-on, decentralized authentication, and open authorization from any device connected to the Internet." Liberty was started by Sun Microsystems and is backed by a plethora of consumer, financial, telco, security, and technology companies. Even AOL has joined up. Given the animosity between Microsoft and Sun, it's probably unlikely that Microsoft will join the alliance. But we can only hope.

More Stories By Anne Thomas Manes

Anne Thomas Manes is a Research Director at Burton Group, a research, consulting, and advisory firm. Anne leads research for the Application Platform Strategies service. Named one of NetworkWorld's "50 Most Powerful People in Networking," in 2002 and one of Enterprise Systems Journal's "Power 100 IT Leaders," in 2001, Anne is a renowned technologist in the Web services space. Anne participates in standards development at W3C and OASIS. She is a member of the editorial board of Web Services Journal. She is a frequent speaker at trade shows and author of numerous articles and the book, Web Services: A Manager's Guide, published by Addison Wesley.
Prior to joining Burton Group, Anne was chief technology officer at Systinet, a Web services infrastructure company, and before that she pioneered Sun's Web services strategy. A 24-year industry veteran, Anne developed her expertise working at a number of the world's leading hardware and software companies. You can reach Anne via e-mail at [email protected] or through her Web site at http://www.bowlight.net.

Comments (1)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


Microservices Articles
Is advanced scheduling in Kubernetes achievable?Yes, however, how do you properly accommodate every real-life scenario that a Kubernetes user might encounter? How do you leverage advanced scheduling techniques to shape and describe each scenario in easy-to-use rules and configurations? In his session at @DevOpsSummit at 21st Cloud Expo, Oleg Chunikhin, CTO at Kublr, answered these questions and demonstrated techniques for implementing advanced scheduling. For example, using spot instances and co...
Skeuomorphism usually means retaining existing design cues in something new that doesn’t actually need them. However, the concept of skeuomorphism can be thought of as relating more broadly to applying existing patterns to new technologies that, in fact, cry out for new approaches. In his session at DevOps Summit, Gordon Haff, Senior Cloud Strategy Marketing and Evangelism Manager at Red Hat, discussed why containers should be paired with new architectural practices such as microservices rathe...
In his session at 20th Cloud Expo, Mike Johnston, an infrastructure engineer at Supergiant.io, will discuss how to use Kubernetes to setup a SaaS infrastructure for your business. Mike Johnston is an infrastructure engineer at Supergiant.io with over 12 years of experience designing, deploying, and maintaining server and workstation infrastructure at all scales. He has experience with brick and mortar data centers as well as cloud providers like Digital Ocean, Amazon Web Services, and Rackspace....
SYS-CON Events announced today the Kubernetes and Google Container Engine Workshop, being held November 3, 2016, in conjunction with @DevOpsSummit at 19th Cloud Expo at the Santa Clara Convention Center in Santa Clara, CA. This workshop led by Sebastian Scheele introduces participants to Kubernetes and Google Container Engine (GKE). Through a combination of instructor-led presentations, demonstrations, and hands-on labs, students learn the key concepts and practices for deploying and maintainin...
Docker is sweeping across startups and enterprises alike, changing the way we build and ship applications. It's the most prominent and widely known software container platform, and it's particularly useful for eliminating common challenges when collaborating on code (like the "it works on my machine" phenomenon that most devs know all too well). With Docker, you can run and manage apps side-by-side - in isolated containers - resulting in better compute density. It's something that many developer...
Modern software design has fundamentally changed how we manage applications, causing many to turn to containers as the new virtual machine for resource management. As container adoption grows beyond stateless applications to stateful workloads, the need for persistent storage is foundational - something customers routinely cite as a top pain point. In his session at @DevOpsSummit at 21st Cloud Expo, Bill Borsari, Head of Systems Engineering at Datera, explored how organizations can reap the bene...
As software becomes more and more complex, we, as software developers, have been splitting up our code into smaller and smaller components. This is also true for the environment in which we run our code: going from bare metal, to VMs to the modern-day Cloud Native world of containers, schedulers and micro services. While we have figured out how to run containerized applications in the cloud using schedulers, we've yet to come up with a good solution to bridge the gap between getting your contain...
In his general session at 19th Cloud Expo, Manish Dixit, VP of Product and Engineering at Dice, discussed how Dice leverages data insights and tools to help both tech professionals and recruiters better understand how skills relate to each other and which skills are in high demand using interactive visualizations and salary indicator tools to maximize earning potential. Manish Dixit is VP of Product and Engineering at Dice. As the leader of the Product, Engineering and Data Sciences team at D...
DevOps is speeding towards the IT world like a freight train and the hype around it is deafening. There is no reason to be afraid of this change as it is the natural reaction to the agile movement that revolutionized development just a few years ago. By definition, DevOps is the natural alignment of IT performance to business profitability. The relevance of this has yet to be quantified but it has been suggested that the route to the CEO’s chair will come from the IT leaders that successfully ma...
Skeuomorphism usually means retaining existing design cues in something new that doesn’t actually need them. However, the concept of skeuomorphism can be thought of as relating more broadly to applying existing patterns to new technologies that, in fact, cry out for new approaches. In his session at DevOps Summit, Gordon Haff, Senior Cloud Strategy Marketing and Evangelism Manager at Red Hat, will discuss why containers should be paired with new architectural practices such as microservices ra...