Thursday Oct 01, 2009

OpenSSO Community changes

Hubert LVGI just saw that my colleague Hubert Le Van Gong has been elected to replace Pat Patterson as the OpenSSO Community Lead.
It is sad to see Pat leaving Sun. Pat has been a source of inspiration in my role as OpenDS Community Manager and we've been collaborating in numerous occasions.
Hubert definitely has the skills and the experience to lead the OpenSSO community and oversee all Sun Identity related open source projects. Another good thing is that Hubert and I are both working out of the Grenoble Engineering Center, in France. So I'm expecting some tighter collaborations between the projects and the communities.
Welcome on the community leadership side, Hubert !

Technorati Tags: , ,

Monday May 18, 2009

OpenDS, OpenSSO and Identity at large

On the first week of May, I was in Munich for the European Identity Conference hosted by Kuppinger-Cole.
This was my first participation and I was delighted to meet with several of the experts in the area as well as some OpenDS customers or users, whom I've mostly "known" only through blogs or emails. I had discussions with Kim Cameron, Jackson Shaw and James McGovern. We shared tea with Felix Gaehtgens and Prateek Mishra. The conference was also the opportunity to talk with and listen to some of my Sun colleagues that I don't get to see often like Fulup Ar Foll and Eve Maler. I must say that both of them did pretty interesting presentations.


Eve's keynote on the first day of the conference brought the case for "permissioned data sharing" and was very well argued. It was the first time that I heard about User Centric identity and VRM tied together and even with a proposed solution.


On Wednesday, Fulup did a very thought provocative (and fast forward) presentation about Digital Identity in the cloud, where he explained the identity management concepts are inherited from a centralized vision of the world and they would not fit well with the cloud, nor scale to the internet. He proposes to look at how mobile operators are solving massive identity scale and to leverage existing SAML2 and Liberty defined services to build the "lazy" identity architecture.

On Thursday I was to take part of a panel discussion on the subject of "The Identity Bus" or the future of Directory Services (should I say Identity Services ?), moderated by Felix Gaehtgens. The panel was an opportunity to see again Steve Shoaff, CEO of Unboundid but previously my manager, and to meet both Dale Olds of Novell and Prateek Mishra of Oracle. I don't know if we've been able to give a good idea of what this "Identity Bus" would look like, but it's definitely "something" in between applications and the data layer, and will probably use a set of protocols like SAML2 and XACML. After the panel, James McGovern asked me when OpenDS will support IGF and CARML. Since both are abstractions and APIs for applications to express their need in term of identity related data, I don't think they are appropriate for an LDAPv3 directory server. But I do see a layer on top of Virtual Directories or Directories that is able to consume those and translate them into appropriate functions.

Right after that Panel, Mark Craig was taking part on a panel discussion on Virtual Directories, along with Sampo Kellomäki of Symlabs, Michel Prompt of Radiant Logic and Keith Grayson of SAP.

On the Tuesday, Pat Patterson and Daniel Raskin hosted the second OpenSSO Community Day, and it was a great success, with over 50 attendees, a day packed of presentations with a very good balance of users and deployers talks vs Sun employees' talks.
Like in New-York, I talked about OpenDS, its goals and roadmap and why it's the perfect companion to OpenSSO as the Users identity store. Most of the presentations from the OpenSSO Community Day have been posted on the event wiki page. And if you could not make it to New-York or Munich, we're having a 3rd OpenSSO / OpenDS / Identity Connectors Community Day in San Francisco on Sunday May 31st at the Moscone center, starting at 1pm. The event is free, but please RSVP. And I hope to see you there.


And congratulations to Pat, Daniel and the whole OpenSSO team, for the Fedlet, winner of the "Best Innovation Award".

Overall, I found the conference really good and interesting and it helped me to put back the work we're doing in the Directory Services engineering team, in the larger picture of Identity management.

Technorati Tags: , , , , ,

Wednesday Nov 12, 2008

Sun OpenSSO Enterprise 8.0 is out

Around 2001, I was collaborating with Jamie's team to build iPlanet Directory Server Access Manager Edition, an addition on top of the successful iPlanet Directory Server.
Many years later, after many branding changes, a tons of new functionalities and supported standards, a successful open sourcing of the code and much investment in ease of use, Sun has just released the first commercial version of the OpenSSO project : Sun OpenSSO Enterprise 8.0.

Sun OpenSSO Enterprise

OpenSSO still makes a great use of LDAP directory servers, but has even gone one step further as it includes an embedded OpenDS directory that can be used as a user store or configuration store, providing an unmatched out of the box user experience.

You can get Sun OpenSSO Enterprise 8.0 now, and if you want to learn more about it refer to the Product page.

Technorati Tags: , , , ,

Wednesday Oct 01, 2008

OpenSSO Enterprise 8 unveiled...

OpenSSO Enterprise 8.0 visual Yesterday, OpenSSO Enterprise 8.0 was launched in SecondLife.

In a very well attended session, Daniel Raskins and Jamie Nelson showed how OpenSSO Enterprise 8.0, known in its last release as Sun Access Manager, adds many new features, as well as being the first commercial release from the open source OpenSSO project.

What impress me most with OpenSSO Enterprise is the amount of work that has been put on user experience, simplifying the life of developers, deployers and administrators. With new features such as the embedded OpenDS LDAP server as the configuration store, the Fedlet, the Identity Services or the Java Web Start Installer

Check out a replay of the SecondLife Launch to get a sense of all the cool new features and capabilities.

Technorati Tags: , , , ,

Tuesday Mar 27, 2007

Paris Identity Management User Group (March 21st 2007)

Last week a Sun Identity Management User Group meeting was held in Paris. The attendance was really good, and in fact exceeded the room capacity as several customers turned out without pre-registering. I was really impressed by the diversity of customers, and the fact that they were coming from all over Europe (Czech republic, Slovakia, Lithuania, Poland, Greece, Italy, Portugal, Germany, Netherlands, Belgium, UK, France, ...).

The Identity Marketing team came in force with Andy Land, Don Bowen and Etienne Remillon (left to right).

Identity Management Marketing Team

Etienne, Directory Senior product manager, presented Directory Server Enterprise Edition 6.0 and demoed the new graphical console : Directory Service Control Center, and Virtual Directory Server.

Overall it was a good day of interaction with our customers, trying to understand their needs and their issues with our identity management products. If you're a Sun customer, using Directory Server or other Sun Identity product, I would strongly encourage you to participate. Your feedback is important for us.

Question and Ansers

Friday Aug 05, 2005

IETF meeting in Paris

This week I was in Paris for the 63rd IETF meeting.

Though I mainly go to the IETF to work on LDAP (both with the LDAPBis working group and as an individual contributor -for example with the LDAP password policy- ), I often go to other working groups and BOF sessions to get a sense of what's going on in the Internet community (at least in the areas that I understand).
And this time, the buz was clearly around the recent vulnerabilities with the use of one-way hash functions such as MD5 and SHA1. With the increasing computation power of computers and the ease of deployment of man-in-the-middle attack, these functions are no longer considered as secure enough. And so are authentication mechanisms based on cleartext challenge-response exchanges. For Directory Server's customers, this means that the way to secure their authentication t0 LDAP is to use TLS either via the use of StartTLS extended operation or LDAP over SSL. Once the connection is secured, the authention could be based on the Simple bind, Sasl Bind with Digest-MD5 mechanism or with exchanged certificates.

On the LDAP front, the participation is diminishing (mainly remains Novell, OpenLDAP and Sun) but the work of revising the LDAPv3 specification for clarification and better interoperability is mainly done. The last remaining issues were hammered this week (hopefully) and we are expecting RFC publication before or around next IETF meeting.

LDAPers in IETF action: Roger, Kurt, Jim and Ludo (left to right).

Tags: LDAP IETF Directory Server

Friday Jun 03, 2005

Planet Identity

I've been running a Sun internal version of Planet Identity for about 6 months now, as a way to follow the very interesting discussions about Identity that are covered in several blogs.
And then came SuperPat and in a couple of days he registered the domain, got the Planet software installed and configured and Planet Identity is now live.
There are already lots of feeds aggregated on Planet Identity, but if you know some that should be there send a note to Pat.

Monday Apr 18, 2005

Victim of Identity theft ?

Just hilarious.

Wednesday Apr 13, 2005

Pretty close to be the winner

Sun Java Directory Server Enterprise Edition 2004Q2 was a finalist in the annual eWeek Excellence Award competition, in the Authentication and User Management category but in the end didn't win, RSA Federated Identity Manager did.

Anyway, Sun won 2 awards in this competition:

Monday Mar 21, 2005

The use (or non-use) of DSML...

SuperPat aka Pat Patterson, one of our expert on Sun Java System Access Manager,  is asking if anyone uses DSML ?
After co-authoring the DSMLv2 specifications with Microsoft, we implemented it in the Sun Java System Directory Server 5.2 nearly 2 years ago, provided some client tools in the Directory Server Resource Kit,  and still we haven't heard of any customer's deployment using DSML.
I did get some reports from the field of some evaluation of DSMLv2, got a few questions with regards to security and authentication, a couple of queries on the performances... but still I have not heard from any use in production.
And the last time I discussed about DSML with a friend who works for Novell, he basically said the same thing.

Still DSML is coming back in conversations some time to time, like today as DSML was mentioned on the OpenLDAP mailing list with a proposed implementation of the client and the server side.

So, I'll re-iterate Pat's question: Is anyone using DSML ?

Wednesday Feb 02, 2005

National secure digital identity card in France

The french goverment is planning on introducing (following some european requirements) a secure digital national Identity program.
The idea is to replace the current national id with a smartcard containing fingerprints and photo (digitally signed) and potentially to use the card for other applications such as medical records, e-voting or banking services...
To make sure that the french government understands  what are the people concerns, it has launched a website for information and discussion including  a forum.

The rest is in french on the site for the "Debat National sur la carte d'identite electronique"

Debat national sur la carte d'identite electronique
L'opinion publique est notamment sollicitee sur les themes suivants : 
  • Le principe de la mise en place d'une carte nationale d'identite electronique sur laquelle une puce electronique contiendrait l'empreinte digitale et la photo du detenteur ;
  • Les garanties souhaitees en termes de protection de la vie privee ;
  • L'acces, depuis cette carte, a d'™autres applications comme des services administratifs (teleprocedures, e-vote...), ou encore des services marchands (services bancaires, achats en ligne, abonnements divers...) ;
  • Les modalites pratiques souhaitees  : lieu de delivrance, prix eventuel d'une telle carte, etc.

Tuesday Nov 30, 2004

A quick and not so dirty HowTo documentation for Directory Server configuration

Dave recently blogged A quick and dirty HowTo manually configure Directory Server, where he explained how to configure Java Enterprise System Directory Server on Sparc from the command line. The good news is that all of what he said was not only fully accurate but based on public interfaces and thus fully supported. The explainations stand for the Java ES version of Directory Server on Solaris (sparc or x86), installed as native packages, and the steps described in his entry are written in our Installation and Tuning Guide. The same steps will also work with Java Enterprise System 2004Q2 Directory Server on Linux, since we also support RPM packages and delivered the directoryserver utility (the path is different though: /opt/sun/sbin/directoryserver). And of course, this will continue to work with Java Enterprise System 2005Q1 which is currently in the beta phase.

Friday Oct 29, 2004

Internationalized Searches with Directory Server

Sun Java System Directory Server does support some powerfull locale specific matching rules, allowing searches according to French, Spanish, Japanese, Esperanto or even Manx.
The list of supported locales is impressive and OIDs have been allocated for each of them. The list is fully documented in the Directory Internationalization Reference" manual.
However, during the re-organization of the documentation for Directory Server 5.2, it appears that the section on how to search using these matching rules was removed.
The documentation of the Directory Server 5.1 on the subject is still valid. It's in the iPlanet Directory Server 5.1 Administration Guide, Appendix B: Finding Directory Entries. The section is Searching an Internationalized Directory and the most important part is the mapping table between Search Types, Operators and OID suffixes..
And below this table, you will find all the examples that illustrate the various searches for internationalized data.

Wednesday Oct 13, 2004

Red Hat acquires rights to Netscape software...

The news have hit the street a few days ago: Red Hat has acquired the rights on Netscape Server products, and among them, Netscape Directory Server.
Vincent Eynard already blogged (in French, no translation available yet) on it and raised many questions.
"They're buying antique software," Joe Keller said, adding that Red Hat's tactical shifts are confusing. "They used to find the best of open source and bring that forward. Now they're buying the oldest of commercial software and making it open source."
It's true that Red Hat has acquired the rights to the software but what they didn't acquire was:
  • A customer base. Currently AOL has almost no enterprise customers outside their own portfolio.
  • Engineering or marketing leadership: They don't have any of either skill set left. Sure, engineers who were left on the way would be please to work again on Directory Server if there is commitment to the product, but most of them have moved to other areas.
  • Market credibility. Netscape hasn't been a player in this space for a long time.

Anyway, the software is old and the market has moved. What customers want is not just a directory server but a robust Identity Data Service. Which is what the Sun Java System Directory Server Enterprise Edition, a product which includes not only the directory server, but also a proxy server for high-availability, security and client interoperability, AD synchronization and an impressive resource kit, delivers today.
I'm not sure I understand Red Hat strategy with this acquisition, but I'm curious to see what will be their position with regards to OpenLDAP which is already part of their platform, and how they are going to manage to open source some software that has non transferable patents (such as Directory Server). And if they succeed to open source it, I'll be watching people's discussions about the code that I wrote more than 3 years ago!

Wednesday Oct 06, 2004

SLAMD has been released as Open Source

SLAMD the Distributed Load Generation Engine has been released as open source release under the Sun Public License. You can download the product from or SLAMD was originally designed for use with LDAP directories and includes a number of utilities and tests that turn a Directory Server benchmark into a kids game. The "how-to" guide for Sun JavaTM Systems Directory Server 5 is also available: Benchmarking the Sun ONE Directory Server 5.2 with SLAMD and MakeLDIF.

This is the blog of a senior software engineer, specialized in LDAP, Directory Server and OpenDS. Ludovic Poitou works in France at the Grenoble Engineering Center, in the Directory Services Engineering team. Outside work, I love skiing and taking photo


« July 2016