|
Comments
|
Today's Top SOA Links
From the Blogosphere Email Address as the Universal Identity
In the brave new world of enterprise applications going to the web do we need an identity directory spawning the internet?
By: Dmitry Sotnikov
Sep. 26, 2009 02:30 PM
Global directories are obviously not new. There were efforts like X.400 and like, but then we kind of got scaled back to company-wide identities instead. So most of us just use a username (or DOMAIN\username) to log into our computer at work, and do not care that this is not globally unique at all. Sounds like the internet will make us care again. Suppose you are designing a global enterprise SaaS application and you absolutely do not want to maintain user identities yourself (because this would obviously be a headache both to you and your customers). Federation is the answer, right? So OK, you go out, pick the federation standard you like (for example, WS-*) and you should not care about user identities. Just redirect users to their actual identity providers – in enterprise world this will likely be Active Directory – and let users in once you hear back that the user is authenticated there. Ay, there’s the rub – you still need to know something about user to decide where to send the user to authenticate. This problem is known as Realm Discovery – even in the federation world you still need to know where the user comes from. Here are a few options which I see: Identity Selector on user computer URL-based discovery The problem is that you probably cannot. Your users will probably want to be able to log in from your generic site as well. Even worse, they might want to delegate tasks in their services to users from other companies – and in this case they will have to learn and supply the CustomerB URL as well when setting up this delegation – which becomes kind of messy. Ask the user Displaying a drop-down list with all your customers is probably not a good idea. DOMAIN\username notation won’t work either – intranet domains are not globally unique. I would argue that email address is probably the only usable solution here:
Where does this lead us? Not only we probably need a global directory, we actually already have one. Long live email addresses.
Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
|
SYS-CON Featured Whitepapers
Most Read This Week |
|||||||||||||||||||||||||||