* Novell and the Bandit Project
Last time out, I mentioned that reputation services was part of the buzz at the recent Internet Identity Workshop. I believe that reputation services show great promise in helping to mitigate risk, which could, in turn, lead to a coalescence of user-centric and enterprise-centric identity. But there was something else that came out of a Novell session at IIW that more directly links the user-centric community with the enterprise identity domain.
Novell’s Dale Olds, who leads the Bandit Project, put on a session called “Open source identity systems in the enterprise.” I’ve mentioned Bandit (and Dale) before in this space, but usually it’s just a passing reference. But it does seem that Bandit is gaining a lot of traction and looking to expand.
The “traction” is in the non-Microsoft CardSpace arena. While the project is self-defined as “…a set of loosely-coupled components that provide consistent identity services for Authentication, Authorization, and Auditing,” the major effort so far has been on working with others, including the Higgins Project and the Pamela Project, to create a non-platform specific implementation of iCards, the generic name for the Info Cards in Microsoft’s CardSpace. Remarkably, this is not done in competition with Microsoft, but in cooperation.
But I’d only known Bandit and its technologies in the authentication space (which is, pretty much, all that CardSpace is doing these days, also). So it was refreshing to hear that Bandit is expanding to look at authorization and audit – and beginning to explore the possibilities of role management. In fact, Version 1 of a roles engine, based on Sun’s openXACML, was released last year. Like most “1.0” versions, it’s valuable more for its potential than for its usability, but Version 2 promises an “RBAC [role-based access control] administrative API” which ups the usability considerably.
There weren’t many corporate “ID guys” at IIW, but all of them were in Olds’ session. If that’s your description, than maybe you should consider his next one. Identity vendors need to be paying attention, also. Few vendors have all the pieces for a complete system. Using open source services to round-out the offering could be an excellent strategy.




