* Ten years later, SSO, identity federation, self-service password change and multi-factor authentication still make up a large part of an enterprise IT road map
In our periodic look back to what was happening 10 years ago, it’s always fascinating to see some of the same topics show up that are in the forefront of our discussions today. The newsletters from March 2000 are no exception.
Early in 2000 I had asked readers to write in and tell me about their directory services plans and problems. I was overwhelmed by the response, and especially by the response from those in healthcare. When I wondered in print why so many of the responses were from healthcare, a reader responded and pointed out that pending legislation — the Health Insurance Portability and Accountability Act (yes, the HIPAA that we’ve come to know and have a love/hate relationship with) — dealt with patient privacy and data security issues. It would demand “role-based” access security to clinical data, and access and audit logs, among other things. Many other things, as we later found out.
The many faces of multifactor authentication
Still, one of the more frequent responses was simply that consolidation within the industry was causing problems due to what we now call “siloing”of identity data. As I wrote:
“I heard from the e-mail administrator of a large group of hospitals. The hospitals are essentially stand-alone as far as IT goes, while using some central administration. There’s a mix of e-mail packages used — Exchange, GroupWise, MS Mail, Lotus Notes mail and cc:Mail. No one wants to give up their present applications and there isn’t any money for something so frivolous as upgrading e-mail systems (probably a version of ‘don’t fix it if it ain’t broke’). All this administrator wants to do is to provide a systemwide address book (i.e., a directory) which is relatively automatically updated.”
Many of you are still working on a similar problem.
But, to me, the most telling response was that from an IT admin who sent me his wish list. First, he hoped to implement an enterprise-wide directory service:
“What the IS department would like to see is Novell Directory Services (NDS) used as an enterprise directory. All of the Oracle applications could use Oracle’s NDS integration features right now, if they can get the vendors to implement it. This would simplify account management across three critical systems. Since NDS is available for OS/390, it could also be used there to eliminate redundant account management for the mainframe. NDS for NT would take care of the NT domain as well.
Most of us have given up that dream and would be content with basic interoperability of our various identity data stores. But he went on:
“After that, my next focus would be to add single sign-on to as many applications as possible, although the majority of these would be included with adding NDS for NT. Our Help Desk spends 40% of its time dealing with password change issues. The next step would be to add Novell Modular Authentication Service to eliminate some of the issues with passwords in general. Since Active Directory will be a product we will have to contend with eventually, I’d like to be able to integrate it into our enterprise directory service. And of course, as we extend services to customers outside our doors via the Internet, I’d like to have eDirectory there to manage that as well.”
SSO, identity federation, self-service password change and multi-factor authentication. Those things still make up a large part of an enterprise IT road map. It’s been 10 years, and we’re not there yet. We have the technology, but the bureaucracy still gets in the way. Is it any wonder IT admins burn out young?




