When I look back to what was in the newsletter 10 years ago, as I do once a month, I frequently feel that I’ve been dropped into an adventure game featuring “…a maze of twisty little passages, all alike” because we never seem to be making much progress.

Back in January 2001, for example, I wrote:

“I had a plea from a reader the other day. It seems he’s been tasked with creating an LDAP-based solution to a problem his company is having and he wanted my recommendation for a good book on LDAP programming.”

I could readily believe that the same question could show up in my inbox today. Oh, it might not be asking about LDAP, of course. It might be XML or OpenID, or Facebook Connect, or WS-Trust or any other hot (or not) technology or buzz phrase. As I replied to that reader:

“Rather than accepting LDAP as the basis for the solution to the problem (and I don’t know what the problem was), he should be clearing the table and simply solving the problem. His boss, or the person who specified LDAP, is the one who needs to rethink.”

To explain, I used an analogy:

“Suppose you had a landscape problem — your two-acre lawn was overgrown. So you tasked your gardener with cutting back on the grass. Only you specified a weed whacker-based solution. Now it’s true your gardener could use a weed whacker to cut two acres of grass, but is it the right tool to use? Wouldn’t a lawn tractor be better?”

Those of us tasked with solving identity-related problems need to resist the efforts of our leaders to try to define either the playing field or the tools for that problem solving.

Of course, I wasn’t prescient when I fulminated:

“LDAP has grown over time to be a catchall for everybody’s directory access tool. It’s changed so much over time, that its original inventors might not recognize it. Yet it still doesn’t do everything that directory architects want it to do. So should we create LDAP 3, LDAP 4 and so on?”

In fact, we did go on to create LDAP3, but the problem remains (or has gotten worse): There is no one solution that fits all identity problems. Use the tools we have, but only when the question (not the questioner) calls for them.