Sun Releases Open Source Tool for Project Liberty 113
ruisantos writes "After submiting the technical specifications for the project , Sun has finally launched an open source tool for its upcoming Sun ONE Identity Server version 6.0, the news can be found on CNET news."
Re:Oh come on (Score:1, Offtopic)
Re:Oh come on (Score:1)
Re:Oh come on (Score:5, Interesting)
My brother works at fedex and they are turning into an all Windows shop.
This assertion is completely and utterly incorrect. It is so far from the truth that one might consider it a deliberate fabrication. Real core production FedEx systems revolve around serious IBM mainframe hardware. Nothing else really supports the necessary transaction volume. Many applications are front-ended by web interfaces running on lots and lots of Sun servers. And Sun boxes being phased out are being upgraded, not replaced. No one at FedEx seriously considers Windows for any core business application, server side. No way it could handle the volumes of data.
For example, one of our smallest non-core-business systems handles maintenance on our vehicles. We periodically look for an off-the-shelf system to buy. Vendors come in all bright and happy and tell us how wonderful their application is. It's easy to use and runs on nice commodity PC hardware under Windows. They tell us they have customers supporting fleets with several thousand vehicles with no problems. And they say it as if we should be impressed about someone operating fleets of 1, 2 or even 3 or 4 thousand trucks. We say, "Great! We have over 160,000 assets, over 60,000 of which are big rigs alone. We have more than 2,000 mechanics scattered over the globe performing 5,000-10,000 different repair actions on those assets every business day, year round, to keep them running. Those repairs generate 500-1000 potential vendor warranty claims per day which must be processed and filed as fast as they are created. And we must automate every possible part of the process chain that we can. Oh, and we need to retain all that data on-line for anywhere from 18 months to 5 years for various business and regulatory reasons. Can your system handle that?" And they look back with a deer-in-the-headlights look and promise to get back to us. And back we go to those old mainframes just chugging happily along, with nice spiffy web front-ends and feeding big honkin' data warehouses on Sun servers. And this is an example of one of the tiniest systems we have! Never mind about really important stuff like flight planning, scheduling or, heaven forbid, the Sort!
Oh, and we can't forget the millions of lines of custom COBOL that have been written and tailored to FedEx business processes. Code that would take some terrible amount of programmer-decades to re-engineer if we ever moved off mainframes.
Just because your delivery-truck driving brother uses a Windows PC at his station or strapped to his wrist does not at all mean that FedEx is in any way using Windows for anything other than client access. We use what makes sense, where it makes sense. For clients, at this point in history that's mostly Windows. For most everything else with really big requirements, Windows just doesn't make sense, whether for reliability, scalability or performance.
Re:Oh come on (Score:1)
To blockquote the original poster:
You might just need to find somebody who's fluently compu-multi-lingual.
Re:Oh come on (Score:1)
COBOL rehosting (Score:1)
http://www.sun.com/migration/mainframe/in
I work for an automaker company (VW Mexico) and we migrate all our mainframe applications to Sun's UniKix platform.
The only hard part is 390 assembler code that needs to be completely rewrite. Fortunatelly we only hade few lines of it. COBOL code run with little change in Sun's E10000. It ends up been way faster and cheaper than the mainframe solution.
If your mainframe has 100 to 500 MIPS you will better try to buy the smallest Sun server that fits that computing power, to reduce even more maintenance costs. Maintanance for a E10000 was half of what we pay to IBM for his mainframe, too much for a Unix server if you ask me...
Sun claims that their new SF15K has 6400 mainframe MIPS... When IBM's G7 has 3000 MIPS. I don't now if that big difference is true, but a good Unix server seems to have comparable power to a mainframe at a lower price point.
The only big difference was the management of the Sun Server. Is not as "profesional" as it was for our mainframe. root account is own by to many if you asks me.. we did have some problems in the initial phase becouse of too many people doing to many things at the same time with root access.
But you better give it a try, at least.
Regards!
Re:Oh come on (Score:2)
Your phrasing reminded me of a passage from Pratchett:
I will now picture "the Sort" as a mind-bogglingly immense task every time I think of FedEx.
Re:Oh come on (Score:1)
When i started to work for FedEx, there was a policy in place - no NT allowed. Oh, how i longer for those days, because at the moment we are 50/50 unix and NT. The reason for this is surely that in our region the load isn't that high as in the US and mostly every country has his seperate little system fullfilling their specific needs (consolidation project has been started just now). This means a bunch of in house developed applications. These applications are written in C or Java, but there are some VB creations running on NT too. Only in the last half year or so there has been interest in linux (before that time there were projects that were not allowed to run on linux, even though the NT server was just acting as web server running IIS).
Anyway at the time of speaking NT has been depreciated unless you have a valid reasons in favor for linux. Even for development, the new strategy is to run/develop on linux and later port over to your UNIX of choice (solaris of hpux).
So yes, there is a high volume of NT in our region, which is not the case for the US.
Re:Oh come on (Score:2)
For most everything else with really big requirements, Windows just doesn't make sense, whether for reliability, scalability or performance.
Sounds like someone's been fed some tall tales from the old grizzled Unix gurus. For the truth on transaction handling, check out the Transaction Processing Perfomance Council's figures [tpc.org]. Oh my goodness, Microsoft's SQL Server rocks them all! How can that be? When you throw as much hardware at it as the mainframe guys do, it blows them all away, because its per-processor performance is higher than all the rest. Oracle has 6615 tpmC per processor, while SQL Server has 9644 tpmC per processor. Tell me again about Wintel's lousy transaction capabilities?
Security (Score:1, Troll)
The question is will Liberty Alliance Project be more secure than passport. Wait, who am I asking? Of course it will be better in security than M$. Who isn't?
Re:Security (Score:1, Troll)
Huh? (Score:4, Interesting)
I don't get it. Is Sun ONE the same as the Liberty Alliance? The article that is referenced doesn't mention Sun ONE that I could see, just the Liberty Alliance.
I didn't even know that the Liberty Alliance was still around since Hailstorm kinda fell through.
I wonder if they're having much luck selling the idea to anyone. Microsoft sure didn't.
Re:Huh? (Score:5, Informative)
Re:Huh? (Score:1)
That's even BETTER than Passport. Lots of organizations out there passing around my private information.
Re:Huh? (Score:3, Informative)
Not quite. Sun ONE is the competitor to the Microsoft
Re:Huh? (Score:1)
Re:Huh? (Score:3, Informative)
The Liberty Alliance is saying: "We don't want your data, we just want to give you the tools".That there is a need for the concept of identity management stands beyond any doubt. How many website logins do *you* have? Exactly. However, how the respective organisation plan to hndle all the data, and plan to implement the concept is what really matters here. That is why the Liberty Alliance has a much better change of actually being used.
Of course, it is an extra kick in the face to MS that the first tool to come out is Open Source.....
Re:Huh? (Score:1)
Re:Huh? (Score:1)
Sun stalling (Score:1)
Re:Sun stalling (Score:1)
Re:Sun stalling (Score:1)
What I was trying to get at is without linux unix was slowly losing common interest. Whether UNIX would be as popular now with or without linux is probably not so debatable, the answer is that it wouldn't be and even Sun has gone as far as admitting that linux has sparked interest in UNIX. Therefore, where was UNIX before linux?
Re:Sun stalling (Score:1)
Open source... (Score:2, Interesting)
As I read in the license it's still 'Intellectual Property bla bla', 5 lines thereafter they define 'Commercial Use'...
What we need is Free Software, not crappy I-wanna-be-cool-but-am-GPL-scared software.
To me this is no better than (oh-the-horror) Microsoft Word
Re:Open source... (Score:2, Interesting)
Re:Open source... (Score:4, Insightful)
SISSL is incompatible with the GPL (Score:2)
Also, would you care to point out where the SISSL is incompatible with the GPL?
From the License List at GNU.org [gnu.org]:
A popular free office suite [openoffice.org] is licensed under SISSL and Lesser GPL, similar to the way Mozilla is licensed (MPL/LGPL/GPL). Unlike the OpenOffice.org suite, this Liberty implementation doesn't seem to also be under a GNU license.
Re:Open source... (Score:2)
Uh (Score:3, Insightful)
Re:Uh (Score:1)
You will have to register in every site.
Browsers only remember username/password information per site.
This is like Microsoft Passport.
You register just once and use your the same username/password across sites.
Re:Uh (Score:1)
Re:Uh (Score:1)
Re:Uh (Score:4, Insightful)
It would be nice if i could use the info on a centralized system. Mind you, i'm just talking about the info. Not about data accumulated from online buying etc.
This is where this system comes in, it allows to store information about a person on a central place while allowing online shops to hold on to their own info. MS Passport tries to gather all the info in one place, prefferably on their own servers.
Re:Uh-Smart Card. (Score:1, Interesting)
It's called a smart card. You go, it goes with you.
If you want something more there. Try a USB keychain device, with smart card features.
Re:Uh-Smart Card. (Score:2)
Re:Uh (Score:1)
Why would my information need to be stored anywhere else?
Plug:
I LOVE Mozilla.
Re:Uh (Score:3, Insightful)
In meatspace, you prove identity by a "collection" of evidence from relatively trusted sources, a bank account, a gas bill and something with a photo. In the on line world being able to go to an online vendor and do a similar thing where you can prove that BANK A, utility co B and Company X all know about a Jo Public of 23 Main Street obviates the need for a "central" repository of identity, which, if you ask me, is a good thing (TM) (ie not having one is a good thing
So in addition to the peoples points about using multiple machines (an excellent point by the way), proof if identity is the killer app INM(NS)HO.
Re:Uh (Score:3, Insightful)
But I agree that there are trust issues.
The other day, me and my friend Kreiger was thumbing through some dumb "technical" magazines while we were in a waiting room, and I saw the news that some phone company had joined the liberty alliance. "Cool," said I and began talking about how this could make sites easier to use, how it was more trustworthy and less evil than Hailstorm. He was saying kinda the same things you are, and I said "It's good for users".
Just minutes after that, we came upon an article about Intels new DRM-iniative. It was totally slanted! "Intel builds in protection against virii and hackers." What the...? I'm totally against DRM and the slant pissed me off! I began complaining loudly about it. Kreiger just looked at me, and said sarcastically:
"It's good for users."
What an eye opener. Paranoia against corporations is my philosophy from now on.
Hello point.... you missed it. (Score:3, Insightful)
And its not just about Web content, its about authorisation systems as a whole.
A browser is just one very very small part of what Liberty could be used for. And while a browser remembers a password, it doesn't know who you are and cannot prove that you are that person.
Version 6.0? (Score:1)
What is point of jumping directly to 6.0
Re:Version 6.0? (Score:1)
Re:Version 6.0? (Score:2, Informative)
SunONE Identity Server 6.0 is the Netscape/iPlanet/SunONE Directory Server (LDAP directory) renamed. It's becoming more than just a directory server, since it becomes an identity and policy management server.
Chris
Direct Link (Score:3, Informative)
Another competitor with better licencing (Score:1)
Same data every time? Bad idea! (Score:2)
You should not be using the same password for all your sites, even if the authentication mechanism never lets the site server have the actual password. If this one password is exposed by your own accident or something, you've basically given whoever has it access to everything. You might as well hand them your wallet, too.
To track spamming leaks, I also give each place which gets my email address a different one. So there's another piece of information that needs to be different. Not everyone yet has the ability to do this, and not everyone will want to. But a lot of people will unless the spam problem gets solved (unlikely).
Anyway, I see major privacy risks in both Liberty Alliance as well as Passport, particularly in not letting people (easily?) control who gets what information.
Re:Same data every time? Bad idea! (Score:1)
Re:Same data every time? Bad idea! (Score:2, Interesting)
There are two excellent tools that I use pretty regularly to keep track of passwords on websites and other services.
Password Safe [sourceforge.net] was origionally developed by Bruce Schneier of . It is open source now. [counterpane.com]
Gpasman [linux.org] is another alternative. I use it on my linux boxes.
I've found them invaluable for keeping track of passwords. Password Safe runs quite happily under wine, and has a tool built in to automatically generate excellent (i.e., almost unrememberable) passwords.
The Slashdot Effect: A new form of terrorism. (Score:3, Funny)
What is the Slashdot Effect?
The Slashdot Effect (also known as Slashdotting) is a new form of denial-of-service attack stemming from the site Slashdot.org. Once they find a 'target' (whether it be a large media company or small personal homepage) the URL of the site is posted on the front page of Slashdot.org. Members of this site attempt as quickly as they can to follow these links and overload the target server. This causes the 'target' website to slow to a grinding halt before going offline. It can sometimes take days or even weeks for the site to recover from such a surge of traffic, and often the servers can be damaged beyond repair (that is, they cannot be fixed with a simple defrag!).
Who is normally the target of the Slashdot Effect and how is it done?
Many American companies have already been attacked by the Slashdot Effect. Targets often include news sites such as the New York Times as well as well as large American companies such as Intel. Sites that criticize the open-source movement are a prime target. For example, lets say an American media website such as the London Times does a review of a little known operating system known as Linux. Linux is an operating system developed by a hacker from communist Finland, which is based on code stolen from an American operating system known as Unix. It was created in cooperation with a communist group known as g.n.u. (Which stands for Glorified Novelty Unix) and is generally unusable by non-hackers. Obviously since it is such an archaic and unstable operating system compared to those made by American companies such as Microsoft it would get a bad review on the London Times. Once a Slashdot member discovers this honest review the URL would be posted on the front page of Slashdot.org. A flood of users would follow the link to the site and bring the server to a grinding halt. Since most of these users are terrorists they would probably have ads disabled using European hacking software. This would mean a potential loss of thousands of dollars worth of ad revenue. To top it off, members of Slashdot.org often plagiarize the articles and post it on illegal mirrors, furthering the loss of ad revenue. Members of Slashdot are rewarded for plagiarizing in the form of 'Karma', a form of hacker currency, on Slashdot.org.
What can I do to avoid the Slashdot Effect and how would I deal with it if it happened?
The easiest way to avoid the Slashdot effect is to refrain from posting anything about any open-source software, especially Linux. Focus your website on fine American companies such as Microsoft. You can also set up your server to reject any links from Slashdot.org, something many people have done. If you think your site is being attacked by the Slashdot Effect, contact the authorities immediately and report this act of terrorism. The penalties against hacker/terrorists are stiff and you can feel confident that the perpetrators of this terror will be punished in the harshest possible means.
by Anonymous Pancake
Re:The Slashdot Effect: A new form of terrorism. (Score:1)
Re:The Slashdot Effect: A new form of terrorism. (Score:1)
"Uh, so your password was rejected?
Have your tried defragging your hard disk?"
Re:The Slashdot Effect: A new form of terrorism. (Score:1)
Re:The Slashdot Effect: A new form of terrorism. (Score:3, Funny)
Ah - I see - Can you post a link to your website that previously got slashdotted?
Many thanks,
Can I run my own personal identity server? (Score:4, Insightful)
If so, then I might have some enthusiasm for it, and I imagine lots of others would as well.
If my identity data is to be stored by some commercial service, even a Liberty Alliance member, I'm afraid I have no plans to participate.
I won't use any website that requires me to sign up for Passport. I've done a lot of Windows development the last couple years, and I can well imagine it would be to my benefit to pay for M$' developer program, but my understanding is that it requires Passport to participate, so I won't have any part of it.
Even if I had my own personal server storing my identity, you can bet I will configure my firewall so it will only accept queries from sites I consciously want to have the information.
And would I need a static IP? (Score:2)
My net connection is kinda primitive out here in the Maine sticks.
I can pay $70 a month for static IP dedicated dialup, which I think is excessive, but at some point I might have to do that. But I imagine most people who might want to run personal servers wouldn't want to pay to have static IP's.
Re:Can I run my own personal identity server? (Score:2, Informative)
Liberty version 1 doesn't make provisions for sharing personal information -- it only defines protocols for federation, single sign-on, federation termination, and logout.
See the Liberty architecture overview [projectliberty.org] (in the specs section on the Liberty web site) for more information.
Re:Can I run my own personal identity server? (Score:3, Interesting)
Mats
Only if your ISP will let you run a server! (Score:2)
WebISO? (Score:2)
Its name spells "piracy" to many companies (Score:2)
what's wrong with Web Initial Signon (webiso nee` pubcookie)?
When I first saw the name "WebISO", I got the impression "download ISOz [i.e. ISO 9660 CD-ROM images that probably infringe a copyright] over the Web". I bet more than one suit will pick up a software copyright infringement connotation [google.com] from that name.
Re:WebISO? (Score:1)
you are referring) work outside of one controlled
domain. There is not a standard way to send
a query (well there is, it is identd, but nobody
does it and it does not work beyond the single
machine level) and find out who you are. AIS is
such a proposal, for web services, as are all the
others.
Let us cooperate (Score:1)
Magical spell is ai-ai-poo!
Microsoft's worst fear coming to pass (Score:1, Offtopic)
It's great to see that vision coming true as major corporate players are actually finding ways to leverage OSS as a competitive advantage, rather than simply sponsoring projects for PR value.
Bill may see threats around every corner, but he isn't often wrong about this stuff. It's great to see these threats actually manifesting themselves. Life is good!
--CTH
Visionary (Score:2)
Bill's approach to reverse engineering is a little edgy: I'd have to say that this approach is illegal under the DMCA, if not previous copyright law.
--CTH
Keep your passwords in a safe at night (Score:4, Interesting)
I think the best solution is to store one's passwords under hard encryption, and keep the physical storage medium in a safe - a physical metal box with a combination lock - when not in use.
I'm not using it yet, but at some point I'd like to get a Palm or Handspring Visor just so I can use Keyring for PalmOS [sourceforge.net] (formerly GNU Keyring).
An alternative would be to put compact flash readers on all my machines and use a compact flash card.
Finally, there is WiebeTech's [wiebetech.com] FireWire KeyChain [wiebetech.com], which stores up to 1 GB of data in a tiny package convienent to hold your metal keys and keep in your pocket.
The advantage of the PalmOS keychain is that it requires no software or hardware support on the computers it is used with, and it can be quickly moved from computer to computer. The advantage of compact flash and WiebeTech's product is that software support can pop the password onto the clipboard for you for convenient pasting into your browser.
Re:Keep your passwords in a safe at night (Score:1)
Formerly, I used gpasman, but since I used multiple computers and OSes, it was not fun. Then, I found keyring, and this is a perfect example of why I like my Palm =)
and under the irony category... (Score:1)
seriously, this actually has a chance, look at the list of members/sponsors at : their website [projectliberty.org]
and the concept of a contiguous online identity is coming anyways, so someone has to offer an alternative to the crap microsoft has been plugging . i'm really looking forward to offering my family members who are just in love w/ what ms already offers something else, running on a secure(r) platform
Comment removed (Score:4, Insightful)
AIS server for the sun offering (Score:1)
[cpan.org]
AIS server
to sit on top of Sun's server?
http://www.pay2send.com/ais/ for more info,
including a working AIS server (although there
is much work to be done on all of it)
Last Post! (Score:1)
Anyone who has been putting off work until they got a round tuit now
has no excuse for further procrastination.
- this post brought to you by the Automated Last Post Generator...
.NET (Score:1)