Wednesday, January 06, 2010

The rising claims tide

Felix Gaehtgens over at Kuppinger Cole blogged about a new webinar series he is hosting on claims. Claims technology is rising in importance as more and more developers and companies start to externalize - or liberate - authentication and authorization from their applications. If you aren't familiar with claims then I would suggest checking out Felix's webinar series.

I briefly laughed while I was reading Felix's description of the first webinar in his series - kicking off on January 14th - which is about Sun's OpenSSO platform. One of the topic areas mentioned is "OpenSSO's proprietary SDK". It was funny to see "open" and "proprietary" in the same sentence.

Despite the laugh, Felix does make a great point. We do need standardization in this area. As Felix states: "Of course I have a side agenda here as well. What I am hoping is that in the end this will promote interoperability – we’re sure that there are some similarities in APIs and services, and hope that vendors will standardise – as users learn more about about these, they’ll put vendors under pressure to standardise their APIs and services."

I completely agree with Felix but I suspect we may see a claims "metadirectory" before we get claims standardized. Some people are going to use "OpenSSO's proprietary SDK" and some people are going to use Microsoft's Geneva and some people are going to use... You get what I mean, right?
in reference to:
"Of course I have a side agenda here as well What I am hoping is that in the end this will promote interoperability – we’re sure that there are some similarities in APIs and services, and hope that vendors will standardise – as users learn more about about these, they’ll put vendors under pressure to standardise their APIS and services"
- Webinar series on Claims | Felix Gaehtgens (view on Google Sidewiki)

Technorati Tags:
, , , , ,

Tuesday, January 05, 2010

Burton Group acquired by Gartner Inc. for $56M!

Just saw the emails flying around about this and thought I'd get a quick post out about it. Amazing news really. I’ve worked with Jamie Lewis, Dan Blum, Gary Rowe and many of the other Burton team since my days at Zoomit. I have always considered Burton to be the best technical analyst firm and Gartner to be the preeminent analyst firm out there. I think this is a dynamite combination.
Congrats to the Burton team and congrats to my friends at Gartner who are really starting off 2010 with a bang! Here’s the email from Jamie Lewis that I received…
Burton Group Acquired by Gartner, Inc. A Message from Jamie Lewis, CEO, Burton Group As we kick off 2010, I’m thrilled to announce that Burton Group has been acquired by Gartner, Inc., the world’s leading information technology research and advisory firm. Given the importance of this news, I want to make sure that all of our clients understand how this acquisition affects them and the services we provide. 

The answer is simple: It won’t. 

Gartner acquired us precisely because of what our clients already know to be true: The practical, technically in-depth advice we provide to frontline IT professionals is very different from the strategic services Gartner provides to CIOs and IT leaders. Together, we will offer a complete world-class solution to every level and functional expert within the IT organization.

The majority of our clients currently use Gartner services as well as ours because they see our offerings as highly complementary and best-in-class for the IT roles and functions we both support. Consequently, Gartner will continue to offer IT1 and other Burton Group research services as separate products. 

Gartner will retain almost all our employees, including 100 percent of our research and consulting staff, so clients will continue to receive the same great value they expect from our company. Gartner also intends to continue our simple, enterprise-wide licensing model that our clients have asked us not to change. Finally, Gartner will increase its investment in our products and services, allowing us to expand our coverage scope to areas many of our clients have asked us to support. 

In short, this acquisition will enable us to provide the best, most complete set of IT research and advisory services available. We are excited to be a part of the leading research and advisory firm in our market, and look forward to bringing the benefits of our acquisition to you, our valued clients. 

On behalf of everyone at Burton Group, thank you for your continuing support. I look forward to updating you on our progress over the coming months. As always, feel free to contact me directly or any of us at Burton Group if you have any concerns or comments at +1.800.824.9924 (USA) or +1.801.304.8174 (international or direct dial).

There's also a blog post by Gerry Gebel here and a letter from the CEO of Gartner regarding the acquisition here. According to The Wall Street Journal, Burton was acquired for $56M in cash.

Does Cloud = Claims?

Laura Hunter (Microsoft), Pam Dingle (Ping) and Patrick Harding (Ping) have been talking about synchronizing passwords to the cloud. Laura’s post, "Syncing Passwords to the Cloud: Sign of the Apocalypse?" was kicked off by Patrick’s “Grounding Enterprise Passwords” and Pam’s “Kick Me for Cloud” posts. As Patrick states:
We are hoping that we can convince everyone that pushing Enterprise passwords into the cloud is a bad idea and in our opinion is certainly not a security ‘best practice’

Monday, January 04, 2010

Speaking of PKI, again!

I’ve been meaning to re-post Dmitry’s blog article on a "New enterprise PKI management console."
Certificate management used to be tough. There have not been a single tool to manage all the aspects of it and administrators had to launch all these certsrv.msc, certtmpl.msc, certutil.exe, ocsp.msc, pkiview.msc, and so on. We had no bulk operations, had to manage each certificate authority (CA) in a separate MMC snapin, and so on.
That is now all a thing in the past with the new PowerGUI/PowerShell-based certificate management admin console created by PowerShell MVP Vadims Podāns (here’s English translation of his blog) and shared for free here. Here’s a very quick summary of some of the features his tool has:
Certificate Authorities management:
CRL Distribution Points (CDP)
Authority Information Access (AIA) settings
Review CRLs
Publish new CRLs
Change CRL publishing periods including overlap settings
Revoked Certificates
Issued Certificates
Pending requests
Failed requests
Issued certificate templates
Revoke/unrevoke certificates
Issue or deny pending requests for certificates
Add/remove certificate templates to issue
Change CRL/CRT/OCSP URL priorities