Monday, June 30, 2008

New VDS Releases

There have been a couple of announcements in the Virtual Directory World.  I would be remise if I did not make mention of them.

Radiant Logic announced (Jun 23) the release of VDS 5.0. Here are some of links from the announcement. Press Release, Government Computer News, DM Review, Campus Technology

The new VDS offers simplified use of virtual directory technology, turning complicated LDAP operations into simple point and click tools. VDS 5.0 has built in wizards and templates to make the most common deployments even quicker and easier.  The new admin console boasts new scenario-driven wizards, so that users can easily deploy various identity and access management tasks.  Scenarios include web access management, Active Directory object and attribute mapping to SunOne (or other LDAP v3 directory server), and Active Directory forest aggregation.  There has also been support added for role-based delegated administration

They also added a very cool new Web-based remote admin console.  If you get a chance, check it out.  It was built on Abode's new Flex technology and has all the features of the server-based console.

As LDAP ages it is important to see that vendors are automating more of the LDAP functions. The need for hierarchal structures still persists, and LDAP is a perfect fit, applications consuming information from LDAP based repositories are not going away anytime soon. I have already heard this new version of RadiantOne VDS referred to as the "VDS for the rest of us". 

Optimal IdM also announced the release of their new Virtual Directory offering today (June 30th), the Virtual Identity Server for Enterprise Group Management.  This is a specialized release of their VD based on .NET to help with the known cumbersome task of AD group management. 

Their close partnership with Microsoft shows in their product.  Not only it is .NET based, they address AD issues with sharp precision.  Certainly Microsoft centered shops should take notice. I also read a good posting about this release on Jeff Bohren's blog. Jeff relates these new tools that are emerging from the virtual directory vendors as specialized "arrows" designed for use for specific problems.  I could not agree more.  You need a "quiver" of tools at your disposal to solve the unique and changing requirements of your identity environment.  Having a flexible identity infrastructure that virtual directories provide, is in my opinion essential. 

 

 

Wednesday, May 21, 2008

Identity and Beyond!!

No, I haven't turned into Buzz-Lightyear. 

I found this diagram today, by accident, by searching information on WAM architecture, it is not into the details I was looking for, but I actually really like it!  Obviously its not just was Web Access Management...  check it out...

This is a logical layer you might see related to identity, security, virtual directory, etc - but could be used for much more.  IdM would just be one consumer of the service layers that are pictured below. 

I have two purposes posting it here:

1) Has anyone seen this diagram before?  I would like to give reference to the owner, but can not find him/her, and see if they have published anything else related here.  (and no, it is not in CISSP Exam Guide, 4th edition - I have a copy and I've already looked.. twice)

2) Let everyone else see this diagram, as I think it is very useful in understanding how virtual directories can be used to solve a lot of problems in the enterprise.  It is a great tool to use as a virtualization engine, and if you have cache involved (amazingly noted also in the diagram) then you have a very performant (yeah, i know its not "officially" an English word, but it should be!) and scalable solution. 

With this approach, you have all the things the "identity gang" has been arguing about - meta, virtual, synch, provisioning, performance, key mapping, etc.

VERY COOL!  So, who is the brilliant one out there?  Come forward and claim your honor due.  :)


Thursday, May 15, 2008

Identity Infrastructure Discussion

Its been awhile since I posted, so here is something I've been wanting to blather about for a couple weeks.  Perhaps when I have more time I can come back and give more specific examples in this conversation where these guys (the "identity gang" or perhaps "the identity thugs" lol) unknowingly are arguing the same point.  Listen to this discussion (link below) and see if you too can pick up on it also.  It is a matter of terminology and perspective. 

This discussion, at least appears to be, an impromptu group conversation on identity bus at the European Identity Conference. Click on the link and go to the Kuppingercole blog and check out the video clip series.

http://blogs.kuppingercole.com/gaehtgens/2008/05/06/identity-bus-round-table-video-online/

What struck me was the differences in terminology. If you listen carefully, you may also notice that often they are talking about the same thing, just from a different perspective. (remember the story about the blind men asked to describe an elephant, having never seen one).  OF COURSE the solutions will be based on a different patterns!  (e.g. loosely coupled vs tightly coupled if they are external or internal to a specific security domain). These guys know this and I'm sure they would agree, but the conversation gets tricky to follow when they switch back and forth.

SO, what is all the fuss around the identity bus? It would give us a way to at least "plug-in" all our related services, so we can transport information in a uniform manner.  You add transformers / connectors (I've given you one of those 'different description for the same thing for free) to plug into the bus and then begin to define how we can interact with the other systems.  THIS IS HUGE.

Increasingly we need to interact with external resources (e.g. remove services, partnerships, federations, etc) and the solutions will look different than what we need to solve identity interoperability inside the enterprise (where we have relatively tight control). 

One thing is clear.  These topics are not an easy ones.  First we need a way to discuss the topic using accurate and consistent terms (at least better than we do now).  We need to build upon ideas and find solutions, without a common communication model, this will never happen.  This goes far beyond just the "bus", we need to define the components and this will help define the conversation.

It is a heterogeneous jungle out there. There is a new project, initiative, concept, etc everyday it seems.... we need to learn and build on concepts.... and move forward. 

(Yes, this was quick and dirty, sorry if I lost anyone, as always contact me if you want more clarification on anything, and thank you for reading my post!)

Wednesday, April 16, 2008

LDAP Directory Proliferation

Matt Flynn posted "Proliferation of Multiple LDAPs" today.  Matt's post was fueled by the recent meta vs virtual debate, which is a nice segway to talking about how to deal with the increasing number of identity stores within the enterprise. 

He suggests examining your current environment, paying attention to these factors:

  • Which data stores have overlapping data and which are unique?
  • Does it make sense to consolidate?
  • Is the data mappable across systems? Do they share unique identifiers?
  • Where can multiple applications share a single store?
  • Where do given applications require access to data in multiple stores?
  • What applications or uses are coming in the future?
  • Which stores are used for critical apps? What is the up time demand?
  • In what format is the data stored?

His article focuses on directories, increasingly common to read referred to as "LDAP stores". Certainly, identity stores revolve around these hierarcal databases, why?  Because of the reliability, performance, and implicit context provided which is a perfect match for security and IAM solutions.

Just some food for thought.  What if you have an application that could make valuable use of information stored in a relational database, a web service, or specialized application?  What now? These types of data stores are proliferating at a higher rate in the enterprise than LDAP directories for sure.   You could...

  1. ignore the possibility of using the data and recreate it (ostrich approach)
  2. replicate the data into an LDAP store (creating potentially complex synchronization requirements and introducing data that is at some level, out of date with the authoritative source)
  3. use the non-ldap source directly (which will probably not be as secure, have the availability, or provide an overall solution for most IAM packages)
  4. use an LDAP proxy to access the information (which will still have the performance problems since a proxy can not perform faster than the underlying data source)

What to do??? By the time you got to my 4th point, you probably were ready to take option #1, admit it... 

Metadirectories are just too expensive, take too long to deploy, difficult to adapt to new sources and/or new synchronization requirements, and the list goes on. People use metadirectories as the "end-all, ubber directory", only to realize the multitude of new requirements not addressed within a year of deployment.  Most virtual directories are too light-weight, offering little more than an LDAP proxy solution. 

Here is my short list of what a solution needs to offer, regardless of your environment.  You needs will change, so your solution should be adaptive and offer more options than you will use today...

  • flexible data representation: able to compose identity objects on proxy or data model views from disparate sources (such as data virtualization platforms offer)
  • performant: yes, I know its not "really" an English word, BUT IT SHOULD BE, we need this word :)  you need to have the reliabilities, availability and overall performance that LDAP compliant directories offer
  • caching options: this includes cache refresh options (i.e. event-driven, TTL, local/distributed, etc)
  • synchronization: at the object and even the attribute level, keep it light-weight, and the option of real-time updates OR not - the choice is the key
  • identity mapping: identities need to be correlated across the data stores, regardless of the data store type and maintained automatically (it is important to have the ability to subsume new sources quickly and effeciently)

 


Monday, April 7, 2008

"Oh, I see now. Virtual *IS* Meta!"

Got to love this posting by Phil Hunt.  I've been watching this bit of diatribe back and forth, especially between Dave Kearns and Kim Cameron.  It's a bit like the old story about six blind men trying to describe what an elephant is, each only feeling one part of the beast. One says "it is like a wall", another "it is like a tree", and so forth. 

SO, are we really talking about multiple problems, or one problem with several aspects?  do we need multiple solutions, or is one elephant enough? 

This discussion is good, and I hope everyone is reading all the posts.  They are essential arguments and these guys are no dummies.

Jackon Shaw << Jackson started it here!! / blog home page
Dave Kearns
Kim Cameron
Phil Hunt
Felix Gaehtgens

if I missed someone, let me know... oh yeah... I put in my two-cents here. :)

Wednesday, April 2, 2008

Worst practices: Exposing IAM blunders

Joel Dubin exposes the most common IAM blunders, and enlightens information security professionals on how to prevent these mistakes. OK, its a bit basic, but they are still problems. I thought the article was uninteresting, but two things caught my attention:

1) multiple logins for multiple applications (listed as the sticky note syndrom)

2) "ghost" passwords - which are more precisely "ghost" accounts, not just passwords, they are logins that should not exist.

If you are correlating any and all identity profiles in your enterprise, then these orphaned accounts can be properly detected AND accounts could be linked to aggregate same-user profiles from the various applications, enabling true SSO. No more multiple logins, no more "ghost" or rogue accounts. 

Utilize an abstraction layer to virtualize sources together, correlate identities, and provide provisioning for identity lifecycle management. Delivering identity data from a central virtualized source can solve this problem.  If your environment is a dynamic and ever changing business (and who's isn't these days) then this is the only way to go. 

read more | digg story

Tuesday, March 25, 2008

Single Sign-On

There was an SSO webinar today by Quest Software.  I would like to thank them for actually putting some content into it and actually explaining what their solutions offer.  I have become a bit weary of webinars so laden with marketing message, you really have no idea what the technology is offering you or if it will fit your infrastructure or not. 

The recording is available here.   My big take-away's had a familiar ring to them, as I have repeated some of these points too many times to count at this point.  Quest has an offering of multiple applications for an SSO package.  Also, check out Mr Shaw's white paper on the subject. 

First SSO means different things to different people; enterprise SSO, Federated SSO, Web SSO, Single Password, Reduced SSO, etc.  But I believe that some things are the same regardless of the "type" of SSO you want to deploy.

Shaw had a nice list of the "perfect world" for SSO:

  • Standards based
  • A single password or login
  • A single directory
  • Strong Authentication support / multi-factor authentication
  • Support for multiple platforms
  • Support for multiple applications
  • Support for "thick, thin, and web applications"

This week I have been faced with some of the problems in solving SSO integration problems and how to deliver identity information to enable SSO.  A client had previously deployed a SSO solution for 35+ applications, using only two sources that were disjointed. Now they were faced with integrating another data source that contained intersection of identities. Some users in the new source exist in one of the other two sources - now the entire SSO solution collapses because it was based on the idea that they would never face an overlap of identities within the repositories.  Again, the answer was to deploy a virtual directory server as the abstraction layer to simplify the management of identities in these, now jointed data sources.

The lesson is, yes you can deploy an application without building a unified infrastructure, but you take a big risk.  When new data sources need to be incorporated (including acquired applications with their respective user-base), you can expect problems. 

PLAN AHEAD.. if you don't need to solve this integration problem now, YOU WILL at some point if you expect any level of scalability.  YES, it is possible to have one source for all your users, without replication.  By using the features of a virtual directory server to create a true union of identities (identities are correlated appropriately and duplicates are eliminated) and extend those entries with additional attributes from the needed data sources, you provide an identity infrastructure to provide authentication and authorization services to your SSO application. 

 

Monday, March 10, 2008

Are Meta-Directories Dead?

My favorite old ranter Dave Kearns (self proclaimed as the old man ranting in the corner) has an article for NetworkWorld, raising the question if meta-directories have any life left in the market.

Although I don't know if meta-directories are dead, they seem to still have a place in the world, I do see an end to this technology in favor or other technologies in the future. The Higgins project is offering a new approach to identity control and management.  Virtual Directories offer a solution, you can check out OVD and RadiantOne who both offer meta-directory type functionality.  (Although Oracle is not explicit how this use case is deployed using OVD since it requires the purchase of additional products, who knows if Oracle has actually tried this or not - you just buy buy buy (story as usual with Oracle right?) until you get the functionality, I have not tried this deployment use case with Oracle personally, I know that RadiantOne offers this functionality out-of-the-box. )

Jackson Shaw (an excellent source of high-quality information regarding in the IdM space) is the source of Kearn's rant, in his more recent posting Jackson again refers to meta-directories as "dead". Shaw also links to Neil McDonald's presentation at the Gartner's IDAM Summit "Everything You Know About Identity Management Is Wrong". 

What is sure is that things are definitely pointing to a big change in how Identity Management projects are deployed.  The time seems right for a major move towards a more manageable, higher level of fulfillment of the promises of IdM applications, and less complexity. 

Noel Yuhanna, principal analyst with Forrester, has some great ideas where this market is going, pay extra attention to "Information Fabric" and "Information as a Service" papers.  It is worth the read if you are planning for the long-term.  I have learned a lot from his materials. 

Another Virtual Directory to Market

Yes, I am a little behind in my postings.  Don't rant against me too much, I have a full-time job ya know!  :)  

I need to add my small voice to the cheers of yet another virtual directory added to the market. Optimal IdM has released their first version of their Virtual Identity Server (VIS). 

The announcement was during last weeks' Directory Experts Conference in Chicago (mainly a Microsoft AD pow-wow, but definitely worth the time).  Although I was not able to attend personally, some of my co-workers did and they felt the event was worth the time.  I do have to note, it is has always been amazing to me how segregated Microsoft centric vs. non-microsoft centric IT shops are.  There were a lot of new people to meet instead of the usual groups that attend the other usual conferences that deal with Identity Management (like Burton's Catalyst, Gartner's IdM Conf, Digital ID World, etc). 

but I digress. .. back to VIS --- 

This newest virtual directory is based on .NET and totally Microsoft AD/ADAM centric.  Focusing mainly on the AD Forest problem (where enabling trust is not an option), the product offers a basic LDAP proxy solution for aggregating (although they call it "union", it appears to really offer aggregation, since I can not find the ability to merge same accounts from different directories into one profile, it requires unique members and identifiers in all connected sources).  They also offer a join, but since their use of "join" and "union" are a bit loose, it is hard to tell the level of sophistication and features they bring to the table.

The bottom line is its great to see another Virtual Directory on the market.  Here is how VIS fits in the overall VDS market...

Virtual Identity Server does:

  • LDAP Proxy
  • Merge and Join directories only
  • Designed for Active Directory / ADAM integration issues; forests, multiple domain controllers, etc
  • Merge of groups from multiple LDAP sources

Virtual Identity Server does NOT have:

  • fully LDAP compliancy local store (if a local store is needed, an instance of ADAM is used)
  • integration capabilities for databases, applications, or web services (at least outside Microsoft, and if it does offer it, it is not explained, although their solution would probably be to use ADAM between such services, which would add more points of failure and complexity, and undoubtedly performance and scalability issues).
  • ability to offer true union of data stores (where matching profiles can be mapped into a single view, they only merge and join) (if you need further technical explanation of this, esp for LDAP folks, let me know - I'm using mathematical definitions of these terms, more common in the database world).
  • meta-directory functionality and/or synchronization capabilities (again they would rely on ADAM, IIS, ILM, which brings nothing new)
  • data model (e.g. for creating new hierarchies / DIT structures)
  • cache (neither memory or persistent)

I am sure the product will evolve, and even though the initial offering is limited, they are offering a solution to a very significant problem, addressing compliancy issues and overcoming serious limitations of AD/ADAM. If you are a Microsoft shop, and don't anticipate the need to integrate from other branded products, then VIS is your choice.  If you have heterogeneous data sources (i.e. oracle, sun, novell) this is not your solution, you need to look at a product like Symlab's Virtual Directory (based on C++) for a more robust LDAP proxy or basic virtual directory for low to moderate volume, or the king of the virtual directories Radiant Logic's RadiantOne Virtual Identity and Context Platform, which offers more features and solutions than any other product I have found in its class by far.  RadiantOne also offers longer "legs" as it offers more features to scale to almost any level.

 

 

 


Wednesday, February 13, 2008

WebDAV Vulnerability Worst of Four Windows Flaws « Bardissi Enterprises Blog

As a lot of us know, there are some serious DOS (denial of service) issues with AD.  AD just isn't fully LDAP compatible, that's the bottom line in my book.  If I have to interface to AD to multiple sources outside Microsoft designed use (inside the NOS), I recommend using a virtual directory to protect AD. Such LDAP packets as described below and other causes of DOS can be dealt with. 

Quoted from http://bardissi.wordpress.com/2008/02/12/webdav-vulnerability-worst-of-four-windows-flaws/:

WebDAV Vulnerability Worst of Four Windows Flaws « Bardissi Enterprises Blog

12 February, 2008

 

MS08-003: Active Directory Denial of Service Vulnerability

Active Directory is the Windows component that provides central authentication and authorization services for Windows computers. Active Directory runs on Windows servers, but also on Windows clients as the Active Directory Application Mode (ADAM) service. Microsoft’s security bulletin warns of an unspecified Denial of Service (DoS) vulnerability involving the way Active Directory handles specially crafted LDAP packets. By sending a malicious LDAP request, a remote attacker could exploit this vulnerability to cause your Windows computer to lock up or to reboot. The attacker could repeatedly exploit this vulnerability to keep your Windows machines offline for as long as he could sustain this attack. However, most administrators don’t allow LDAP traffic (TCP ports 389 and 3268) through their perimeter firewall. Therefore, this vulnerability primarily poses an internal threat.
Microsoft rating: Important.

 

Wednesday, February 6, 2008

Oracle Virtual Directory Webinar

I thought I would share an interesting webinar on virtual directories recently from Oracle on their virtual directory (OVD).

You can view the recording here.

This is the first time I've mentioned a product by name, and referenced a particular company. I try to stay as neutral as possible, perhaps out of habit due to my role to help customers decide. I usually always give at least two options for any decision and list the pro's and con's.

This webinar is a little generic, although I was able to get in a couple questions which the moderator answered decently. OVD certainly has a place in the marketplace and a specific role.

If you want an introduction at a high-level for what a virtual directory can do for you, this is a great resource so check it out.

What OVD doesn't do is offer solutions to more complex integration problems that you can face that require more feature sets, which Oracle will gladly provide to you, of course, at an additional price, as part of their IdM Suite, such as synchronization capabilities, data modeling, provisioning services, and more...

Monday, January 28, 2008

Problems extending Active Directory Schema

Jackson Shaw blogs about still MORE issues that are arising from trying to update schemas in active directory. This is why I encourage people NOT TO TRY THIS AT HOME (or at work). It's disruptive and can have some serious effects on your network infrastructure. Use the existing schema in a virtual directory, extend the schema there. Then you don't have to worry about the issues involved here. Point the applications that need this schema extension to the virtual directory instead of AD. Most virtual directories will let you mount an existing structure (proxy) and extend the entries from various data sources (including data bases, other directories, applications or web services). Some virtual directories will even allow a join function to extend the entry from its own local store if the needed schema attributes do not currently exist. Kind of neat huh? So why all the drama? I think people just don't understand this technology - you can use your existing stores and pretty much do anything you want with them, without replication. Performance you say? Well, if it really becomes a problem, there are several caching options and cache refresh options in virtual directories also. If you don't have a virtual directory (or one that has these options) in your arsenal, get one - it will save you a lot of headaches, and a lot of time. Become the famed Engineer Mr Scott of Star Trek fame and get everything done in one third the time or less!

read more | digg story

Friday, January 25, 2008

Matt Flynn Blog, Burton Group, affirm Virtual Directories as a Valuable IdM infrastructure component

Matt (see http://360tek.blogspot.com/2008/01/year-of-virtual-directory.html) asserts his continued position as an advocate of using virtual directories- and references Burton Group's affirmation of this technology as well in a recent webinar. Burton also published a paper recently (Nov'07) "Virtual Directories: Valuable Present, Promising Future" that is great information on the state of the vendors in this market and their capabilities. Not all of them have all the flexibility that Matt refers to "That is, virtualizing the data structure, access protocols, server locations, etc. and presenting the same useful data from its original source in real time (or cached) in virtually any format and over most common data interfaces." The Burton Group study will help a lot in sorting that out.http://identityinfrastructure.blogspot.com/

read more | digg story

Thursday, January 24, 2008

Weakness in IdM Products

http://duckdown.blogspot.com/2008/01/common-weakness-in-all-identity.htmlThis author takes a harsh, but not well versed stand, into criticizing ALL IdM software packages out there for the lack of integration into various data stores, especially Active Directory. If it were that simple, don't you think all the vendors would do it? Just the fact that the symptom is there for ALL IdM packages, should tell you there is MORE to the story, no??? First check out Gavin's response, a good one - and saved me from more ranting on here... http://blog.suretecsystems.com/archives/77-A-Common-Weakness-in-all-Identity-Management-Products,-but-not-OpenLDAP.html First - Active Directory is for INTERNAL users primarily. Not useful for all IdM initiatives, say for a partner portal, or federated business environment where the user list is NOT your network users. Second - If you know much about Active Directory you will know 1st AD admins don't want you messing with it, you can cause serious problems if you do - extending schemas, customer object classes, etc pose problems, plus its SLOW - HENCE why ADAM exists in the first place, but then why isn't everyone clamouring over the use of ADAM? Like Gavin Henry says... I encourage this author to take a look at the white paper Open LDAP wrote (http://symas.com/documents/Adam-Eval1-0.pdf) and you will start to see the limitations and disjointed nature of LDAP compliant directory services and AD.

read more | digg story

Completeness of Metadata

http://www.b-eye-network.com/view/6722 This is just kind of interesting, nothing great... BUT the issue of how you do handle large amounts of metadata does ring true. The author states that perhaps you must limit your metadata and not try to get a complete picture. Of course you do! You must limit it to the context in which it is relevant! This is why I think the hierarchal views found in directories are great, they can give you direct context of data, natively (i.e. look at the DN of a user object) - if you build these trees correctly you have some great information to leverage. Let's take it one step further, look at a virtual directory - where you can change the labels and tags as you want, giving the DN a more explicit meaning.If your confused, don't feel bad, I've confused many on this topic - but if you can get your head around it, it will pay off!!

read more | digg story