Archive for the Identity Management Category

OSS IDM System - Some Thoughts

Been a while since I’ve posted anything. My apologies if anyone is actually reading this stuff.

I’ve been thinking a lot more about that first question I ever posted.. “Wheres my opensource IDM solution”. And I certainly received some messages from a few people that pointed a few out to me - They all looked fairly promising.

But, I keep wondering if it would be possible to write a module that attaches itself to an openldap server (sort of like a persistent search on steroids) that could subscribe to changes that occur there. That way, you could use openLDAP as a “meta-directory”. From there, you could write connectors that connect to target systems.

This seems a lot like Novell’s IDM, only sort of the opensource brother to it.. without the XML/DirXML engine… (which i imagine is patented somehow anyways).

Any thoughts? Im just kind of rambling on here….

Open Source IDM Solutions

In a previous post, I noted that I had not seen any open source IDM solutions that were really focused on provisioning. I had seen quite a few that were focused on SSO and federation. After my post, a blogger pointed out to me a company called Diamelle that had something in that space. To be frank, I havn’t had any spare time to dive into it. But, on the surface, and from what I’ve read, it looks like it could have some good traction.

Another one has popped up since then called Velo. I saw it in response to this post. From the looks of it, it appears to be playing heavily in the provisioning space. Also, it appears to be offered under the GPLv2.
I watched the 2 demos they had up on their website, and it appears to be a descent looking interface. Im assuming its a push/pull type of technology, but I could be wrong since I havn’t actually used it. Either way, more choices in the IDM provisioning space can only be a good thing. Ill be checking this one out next chance I get. So far though given Diamelle, and Velo, at least there are some choice out there.

This is actually pretty cool.

A few days ago, I put up a little article asking where my open source IDM solution was. Looking across someone elses blog, I was directed to this link here.
Its a very cool mapping tool used to create a map of known open source IDM projects and their status. I found this very helpful. Maybe you will as well.
Banner

Started PAM module list

I just started putting together a list of all the pam modules I can find that are open source. It can be found here.

I’ve been getting a bit frustrated at finding some of these. Many of these are very useful! And it would be nice to a one place to go to find out about some of these… Sooo.. im starting this little list and updating it as i come across them.

Mark.

Where’s my open source enterprise IDM solution?

I’ve been doing IDM for about 6 years now. With everyone I speak with, IDM pretty much gets talked about in 2 ways.
1 - SSO/Federation solutions. Geared mostly around federation and SSO Access/Authorization. (there are actually a plethora of Opensource projects that can help tackle these problems).

2 - IDM in terms of user provisioning and profiling in the enterprise to enterprise type software. Such as Lotus Notes, Active Directory, eDirectory or even things like RACF on zOS.

For number 1, I’ve found all sorts of stuff in that space.. heres a couple of links for it…

http://www.manageability.org/blog/stuff/single-sign-on-in-java/view

http://www.techworld.com/networking/features/index.cfm?featureid=1681

For number 2 though, I have yet to find anything interesting that gets my attention. Which got me wondering why?

Im well versed in Novell’s Identity Manager product as well as have done *some* work with Sun’s product. There are also a few other companies out there that claim to do some form of IDM in this space, including Microsoft, IBM/Tivoli, CA, and then there are some smaller players.

Most of these products base everything on some sort of a directory technology. Be it eDirectory for Novell, AD for microsoft, or whatever the directory of the day is… they all have some form of directory back-end that serves as a meta-directory. In the opensource world, we have openldap which is certainly a reputable and well proven directory service. Seems to me, that it would be a relativley interesting idea to attempt to build an enterprise class IDM solution that works in conjunction with open-ldap as the back end.

I realize, I’m sort of rambling on here, so if anyone knows of any efforts going on in this space, post a comment.

I’m actually considering attempting this myself. If there is any interest, let me know!

UPDATE: from one of the little handy “Whos linking to you links” Someone pointed this out… http://www.diamelle.com/ . They appear to be working on this exact problem.. ill check it out and let everyone know.

|