Identity management for objects, services as well as people

Opinion
Jul 29, 20043 mins

* Chris Stone talks up identity management in the enterprise

I do give Chris Stone a hard time in this newsletter and in person. Frequently he deserves it. But there are also times he deserves everything nice I can say and this is one of those times.

I do give Chris Stone a hard time in this newsletter and in person. Frequently he deserves it. But there are also times he deserves everything nice I can say and this is one of those times.

Last week at the Catalyst Conference, Stone gave a keynote address entitled “Identity Based Computing.” It was all about how identity is intrinsically important to everything you do with a computer, on the network and across the Internet.

As he said, the directory vendors (primarily Novell, of course) have done such a good job of selling us on the benefits of identity-based computing that people are the best managed part of the enterprise and its systems. Password management, single sign-on, electronic provisioning, access management, audit services and more  – all of which are provided by NetWare, eDirectory, and the upcoming Open Enterprise Server – provide for end-to-end lifecycle management of all of the network’s users. So why stop there?

Why not apply what we know, what we’ve learned and what we can do with the people in the enterprise to the other IT systems we use everyday – servers, routers, other devices, applications, services, etc.? All that’s needed is to change one word in our definition of digital identity. Instead of defining it as “the representation of the distinguishing characteristics of a USER in a digital system,” make it “the representation of the distinguishing characteristics of an ENTITY in a digital system,” where that entity is any person, place, or thing that can be represented as an object in the directory.

Now this is something that Novell’s ZENworks has hinted at and pointed to, but now Stone is suggesting you use the same template to handle other systems such as resource management and collaboration solutions. As just one example, he pointed out that both user accounts and enterprise hardware resources go through analogous stages of lifecycle management: with users it’s hire, move, promote, move, and terminate, while with equipment it’s buy, secure, distribute, maintain and retire.

He also suggested a compound form of identity based on context (who, what, when, where, why) with the user ID concatenated with the platform and service IDs authenticating to the directory and gaining access based on what resources were wanted and where they would be used. Context-based identity is a brand new area (although Novell’s multi-factor authentication service helped pioneer the technology) and it’s good to see “the NetWare company” leading the way.

While Stone did use the “p” word (“Change the paradigm!”), I won’t hold that against him because he’s showing you how to take the expertise you’ve learned through NetWare user management and apply that to every facet of your organization – and use eDirectory and NetWare to tie it all together. Think about it.