Welcome!

Microservices Expo Authors: Flint Brenton, Liz McMillan, Elizabeth White, Charles Araujo, Ed Witkovic

Related Topics: Microservices Expo

Microservices Expo: Article

Identity CrisisPassport may not fill the need for a global identity service

Identity CrisisPassport may not fill the need for a global identity service

Do you have a .NET Passport identity? You may not realize it, but chances are reasonably high that you do. If you have a HotMail or MSN account, Microsoft assigned a Passport identity to you automatically. Microsoft claims to have more than 160 million users registered in the Passport identity service.

Pretty soon you'll need a Passport ID to have any interaction with Microsoft. In December 2001, quite a few gamesters were surprised to discover that their old accounts at the Microsoft Zone gaming site wouldn't work without a Passport ID. Microsoft also requires a Passport ID to join MSDN, to register for a Microsoft seminar, or to access Microsoft's node in the UDDI public registry. The new Windows XP Product Activation (WPA) system uses Passport by default. You can also use your Passport ID to log in to your XP system.

So just what does a Passport identity do for you? Obviously, it lets Microsoft track your activities, but that's not a particularly strong incentive for most users. Most consumers view Passport as an electronic wallet. You can associate a credit card with your Passport ID and use it to buy things at any site that supports Passport Express Purchase. This sounds pretty useful, except that Microsoft hasn't been especially successful in recruiting e-tailers to support Passport (there are less than 100 participating sites so far). Even so, Passport can fill in Web forms for you, alleviating the need to type in your name and address at every site.

But Passport has a much more useful role to play in the future, particularly in the realm of Web services. Passport provides a cross-corporate single-signon service, which is critical to allow Web services to work together.

Today most Web services work alone, but in the future we want to be able to assemble multiple Web services to create more powerful business services. First we need to provide a way to let Web services share information.

Consider how most Web services implement security today. Each business that offers a secure Web service maintains a list of authorized users, who authenticate themselves using a userid and password. When we start assembling Web services, we don't want to force the user to type in a userid and password for every Web service involved in the aggregate business service, and we don't want to force Web service providers to develop point-to-point security connections for each Web service assembly effort. Instead, we need a facility that enables single sign-on across any number of Web services operated by any number of businesses. What we need is a global identity service.

Passport could be used as a global identity service but there is one serious impediment. Passport isn't open. Microsoft intends to collect revenue from businesses that use Passport for authentication. While I will grant that Microsoft has the right to make money from its innovations, I suspect that not every business wants to pay Microsoft to manage its authentication process. And many businesses won't be inclined to let Microsoft own their customer information. Hence, I doubt that Passport will ever become the de facto global identity service.

In September Microsoft announced plans to "open up" Passport by adding support for Kerberos V5, but this feature still won't make Passport open. What it means is that Passport will be able to access your internal user management system (such as Active Directory) to retrieve user identity information, assuming, of course, that it supports Kerberos V5.0. (I probably don't need to tell you that Active Directory supports Kerberos V5.0.) Keep in mind that although you would be managing and maintaining your own list of authorized users, all identity and authentication requests still need to go through Microsoft's Passport service, allowing Microsoft to collect a toll.

It would be a lot better if there were standards associated with Identity that would allow anyone to set up an Identity Service so that any Web service could authenticate users using any Identity Service. This approach would allow users a wide choice of Identity options. Personally, I'd feel much more comfortable giving control of my financial information to my bank than to Microsoft.

Standards for Identity would include an XML format that represents user information and an API that is used to access any compliant Identity Service. The Liberty Alliance Project, which is working to define Identity standards, says it intends "to create an open, federated solution for network identity - enabling ubiquitous single sign-on, decentralized authentication, and open authorization from any device connected to the Internet." Liberty was started by Sun Microsystems and is backed by a plethora of consumer, financial, telco, security, and technology companies. Even AOL has joined up. Given the animosity between Microsoft and Sun, it's probably unlikely that Microsoft will join the alliance. But we can only hope.

More Stories By Anne Thomas Manes

Anne Thomas Manes is a Research Director at Burton Group, a research, consulting, and advisory firm. Anne leads research for the Application Platform Strategies service. Named one of NetworkWorld's "50 Most Powerful People in Networking," in 2002 and one of Enterprise Systems Journal's "Power 100 IT Leaders," in 2001, Anne is a renowned technologist in the Web services space. Anne participates in standards development at W3C and OASIS. She is a member of the editorial board of Web Services Journal. She is a frequent speaker at trade shows and author of numerous articles and the book, Web Services: A Manager's Guide, published by Addison Wesley.
Prior to joining Burton Group, Anne was chief technology officer at Systinet, a Web services infrastructure company, and before that she pioneered Sun's Web services strategy. A 24-year industry veteran, Anne developed her expertise working at a number of the world's leading hardware and software companies. You can reach Anne via e-mail at [email protected] or through her Web site at http://www.bowlight.net.

Comments (1) View Comments

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


Most Recent Comments
JP Morgenthal 03/17/02 07:03:00 PM EST

Just my $0.02, but I've been trying to get the attention of Liberty Alliance for an Associate membership, but no-go. The doors are closed to anyone not willing to fork over $120K US. Hey, Microsoft may not be a standard, but I have a little more in my pocket at the end of the day using Passport right now.

@MicroservicesExpo Stories
Don’t go chasing waterfall … development, that is. According to a recent post by Madison Moore on Medium featuring insights from several software delivery industry leaders, waterfall is – while still popular – not the best way to win in the marketplace. With methodologies like Agile, DevOps and Continuous Delivery becoming ever more prominent over the past 15 years or so, waterfall is old news. Or, is it? Moore cites a recent study by Gartner: “According to Gartner’s IT Key Metrics Data report, ...
Agile has finally jumped the technology shark, expanding outside the software world. Enterprises are now increasingly adopting Agile practices across their organizations in order to successfully navigate the disruptive waters that threaten to drown them. In our quest for establishing change as a core competency in our organizations, this business-centric notion of Agile is an essential component of Agile Digital Transformation. In the years since the publication of the Agile Manifesto, the conn...
In his keynote at 19th Cloud Expo, Sheng Liang, co-founder and CEO of Rancher Labs, discussed the technological advances and new business opportunities created by the rapid adoption of containers. With the success of Amazon Web Services (AWS) and various open source technologies used to build private clouds, cloud computing has become an essential component of IT strategy. However, users continue to face challenges in implementing clouds, as older technologies evolve and newer ones like Docker c...
The next XaaS is CICDaaS. Why? Because CICD saves developers a huge amount of time. CD is an especially great option for projects that require multiple and frequent contributions to be integrated. But… securing CICD best practices is an emerging, essential, yet little understood practice for DevOps teams and their Cloud Service Providers. The only way to get CICD to work in a highly secure environment takes collaboration, patience and persistence. Building CICD in the cloud requires rigorous ar...
"This all sounds great. But it's just not realistic." This is what a group of five senior IT executives told me during a workshop I held not long ago. We were working through an exercise on the organizational characteristics necessary to successfully execute a digital transformation, and the group was doing their ‘readout.' The executives loved everything we discussed and agreed that if such an environment existed, it would make transformation much easier. They just didn't believe it was reali...
All organizations that did not originate this moment have a pre-existing culture as well as legacy technology and processes that can be more or less amenable to DevOps implementation. That organizational culture is influenced by the personalities and management styles of Executive Management, the wider culture in which the organization is situated, and the personalities of key team members at all levels of the organization. This culture and entrenched interests usually throw a wrench in the work...
"Opsani helps the enterprise adopt containers, help them move their infrastructure into this modern world of DevOps, accelerate the delivery of new features into production, and really get them going on the container path," explained Ross Schibler, CEO of Opsani, and Peter Nickolov, CTO of Opsani, in this SYS-CON.tv interview at DevOps Summit at 21st Cloud Expo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.
The purpose of this article is draw attention to key SaaS services that are commonly overlooked during contact signing that are essential to ensuring they meet the expectations and requirements of the organization and provide guidance and recommendations for process and controls necessary for achieving quality SaaS contractual agreements.
What's the role of an IT self-service portal when you get to continuous delivery and Infrastructure as Code? This general session showed how to create the continuous delivery culture and eight accelerators for leading the change. Don Demcsak is a DevOps and Cloud Native Modernization Principal for Dell EMC based out of New Jersey. He is a former, long time, Microsoft Most Valuable Professional, specializing in building and architecting Application Delivery Pipelines for hybrid legacy, and cloud ...
The “Digital Era” is forcing us to engage with new methods to build, operate and maintain applications. This transformation also implies an evolution to more and more intelligent applications to better engage with the customers, while creating significant market differentiators. In both cases, the cloud has become a key enabler to embrace this digital revolution. So, moving to the cloud is no longer the question; the new questions are HOW and WHEN. To make this equation even more complex, most ...
CloudEXPO New York 2018, colocated with DXWorldEXPO New York 2018 will be held November 11-13, 2018, in New York City and will bring together Cloud Computing, FinTech and Blockchain, Digital Transformation, Big Data, Internet of Things, DevOps, AI, Machine Learning and WebRTC to one location.
Docker is sweeping across startups and enterprises alike, changing the way we build and ship applications. It's the most prominent and widely known software container platform, and it's particularly useful for eliminating common challenges when collaborating on code (like the "it works on my machine" phenomenon that most devs know all too well). With Docker, you can run and manage apps side-by-side - in isolated containers - resulting in better compute density. It's something that many developer...
In his keynote at 19th Cloud Expo, Sheng Liang, co-founder and CEO of Rancher Labs, discussed the technological advances and new business opportunities created by the rapid adoption of containers. With the success of Amazon Web Services (AWS) and various open source technologies used to build private clouds, cloud computing has become an essential component of IT strategy. However, users continue to face challenges in implementing clouds, as older technologies evolve and newer ones like Docker c...
"We're developing a software that is based on the cloud environment and we are providing those services to corporations and the general public," explained Seungmin Kim, CEO/CTO of SM Systems Inc., in this SYS-CON.tv interview at 21st Cloud Expo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.
We all know that end users experience the internet primarily with mobile devices. From an app development perspective, we know that successfully responding to the needs of mobile customers depends on rapid DevOps – failing fast, in short, until the right solution evolves in your customers' relationship to your business. Whether you’re decomposing an SOA monolith, or developing a new application cloud natively, it’s not a question of using microservices - not doing so will be a path to eventual ...
Explosive growth in connected devices. Enormous amounts of data for collection and analysis. Critical use of data for split-second decision making and actionable information. All three are factors in making the Internet of Things a reality. Yet, any one factor would have an IT organization pondering its infrastructure strategy. How should your organization enhance its IT framework to enable an Internet of Things implementation? In his session at @ThingsExpo, James Kirkland, Red Hat's Chief Archi...
Containers and Kubernetes allow for code portability across on-premise VMs, bare metal, or multiple cloud provider environments. Yet, despite this portability promise, developers may include configuration and application definitions that constrain or even eliminate application portability. In this session we'll describe best practices for "configuration as code" in a Kubernetes environment. We will demonstrate how a properly constructed containerized app can be deployed to both Amazon and Azure ...
We all know that end users experience the internet primarily with mobile devices. From an app development perspective, we know that successfully responding to the needs of mobile customers depends on rapid DevOps – failing fast, in short, until the right solution evolves in your customers' relationship to your business. Whether you’re decomposing an SOA monolith, or developing a new application cloud natively, it’s not a question of using microservices - not doing so will be a path to eventual ...
We all know that end users experience the Internet primarily with mobile devices. From an app development perspective, we know that successfully responding to the needs of mobile customers depends on rapid DevOps – failing fast, in short, until the right solution evolves in your customers' relationship to your business. Whether you’re decomposing an SOA monolith, or developing a new application cloud natively, it’s not a question of using microservices – not doing so will be a path to eventual b...
The past few years have brought a sea change in the way applications are architected, developed, and consumed—increasing both the complexity of testing and the business impact of software failures. How can software testing professionals keep pace with modern application delivery, given the trends that impact both architectures (cloud, microservices, and APIs) and processes (DevOps, agile, and continuous delivery)? This is where continuous testing comes in. D