Cc: Russ DeVeau <[email protected]>
From: Brett McDowell <[email protected]>
Subject: Re: private and confidential - but can I get a quote from you?
Date: Fri, 25 May 2007 13:56:16 -0400
To: Doc Searls <[email protected]>
X-Server-Quench: 4ac3618b-0ae9-11dc-a443-001185d377ca
X-Report-SPAM: If SPAM / abuse - report it at: http://www.authsmtp.com/abuse
X-Virus-Status: No virus detected - but ensure you scan with your own anti-virus system!
After 5 more minutes of thought I think I can put a more succinct Linux spin on all of this.
Vista is arguable more advanced than Linux as it has web services technology baked into the OS, all the way down to the metal. Folks like Intel are driving technology standards in Liberty Alliance that provide a framework for identity-based web services interoperability all the way down to the metal (trusted module functionality in the chipset, leveraged by the OS to talk to network applications who must consume trusted identity data for authentication and authorization). Linux must take advantage of web services in the OS itself, as Vista has (and OS X likely will but Apple is absent from all industry fora and very secretive). Concordia is the opportunity for Linux to evolve into a full-class identity web services platform because it is designed to deliver the interoperability of ID-WSF on top of the same protocol family that drives Vista (WS*). Oh, and it will tie all of this into openID so the Web 2.0 platform is a full-class participant in these types of transactions.
It's fun to think about this from the linux perspective, not something I normally focus on.
-- Brett
On May 25, 2007, at 1:35 PM, Brett McDowell wrote:
Yes, there is a linux angle. I think it goes something like this (nothing below is vetted enough for quoting it is more of a rough sketch of how I see things)...
Linux is *the* open source platform for Identity Management (IDM)
open source is highly dependent on open standards
protocol standards (like those required for federating identity & implementing web services) are zero sum standards, you cannot have these kinds of network functionality if you have to code to duplicative protocols or moving targets... without interoperability there is no point in coding in the first place. This is a zero sum game (where things like doc formats are not, necessarily).
identity-based web services (can you think of a web service without identity?) is a key enabling technology for the current and future of computing
Linux and Windows are both platforms for IDM
Windows has a protocol stack for IDM and identity-based web services, WS*. Linux could use that, after MSFT does (the lag time to standardization that they are infamous for)
But WS* components do not = interoperability. They are below the interop layer. You still need a well defined web services framework for interoperability using WS*. MSFT knows how they implement WS* in their products, but for you to find out you must go to them. Given their current friendliness toward the linux community, I can give you 235 reasons why they are not likely to cooperate.
Have no fear, ID-WSF (Identity Web Services Framework) from Liberty Alliance solves this problem. It provides interoperability through well defined profiling of component specifications. But there's a catch... Liberty produced ID-WSF 1.1 in 2004 and ID-WSF 2.0 in 2006 while MSFT didn't release the relevant WS* components to OASIS until sometime afterward. Now you have a problem. MSFT stuff is build on WS*. ID-WSF is the profile you want but was not built on WS*. Someone needs to change something or we have competing protocol stacks. That's the reality of today, two stacks and Linux (like all major IT vendors) needs to implement both to be a full-featured, interoperable platform for IDM and identity-based web services.
...but there's hope...
Concordia is a project to accelerate interop, harmonization, and ultimately convergence of ID-WSF and WS* (and openID). The architects of both stacks are at the same table for the first time in history (forced their by their customers who demand a solution) and they are working this out. What does the future look like?
ID-WSF on WS* and Linux will benefit from that convergence. In the meantime its one stack or the other (or both). Linux will benefit from that convergence even more if the linux community participates. Novell and Sun are there, but what about the other disto's or open source solution vendors like Jboss, etc.?
-----
That's crude but I think the story goes something like that. I know you haven't been knee-deep in the WS*/ID-WSF discussions so I'm trying to convey the gist as quickly as possible. Feel free to ping me with clarifications or reference points to get other perspectives beside my own.
P.S.
I've downplayed openID in Concordia in the story above but it is a very relevant issue. The short story about openID and Concordia goes something like this....
> openID 1.X is light and works
> openID 2.0 is duplicative to SAML & ID-WSF
> Concordia is working on ways to bootstrap openID 1.X to ID-WSF (work is underway now!)
> Concordia is likely to have openID on the same solution continuum that SAML and ID-WSF are on... fully embraced by the Liberty contingent and Cardspace contingent
> The net result of ID-WSF on WS* also gives you Cardspace interoperability (which I failed to mention above)
> Liberty Alliance tests products for interoperability to ID-WSF, and we will continue to do that after convergence (i.e. you can imagine Cardspace and ADFS going through that certification program... if you were really, really optimistic :)
|| Brett
On May 10, 2007, at 12:49 PM, Doc Searls wrote:
I'd love to say something, but my problem is that I'm also press (through my work as an editor with Linux Journal), and we have a policy of not putting our names on the supply sides of press releases.
I would be glad to give Concordia plenty of support otherwise, though.
Is there a linux angle to it? That way I could get something in the July Linux Journal, today. (Working on it right now.)
Doc
At 8:10 AM -0400 5/10/07, Brett McDowell wrote:
(please do not forward this (or blog this) without checking in with me first)
Doc,
I have been scratching my head about who to seek out from the "user-centric"/"grassroots" community for a quote in this press release. I have decided you are the best and most visible representative of that community. Therefore I would like to get a quote from you for inclusion in this press release that will hit the wire early next week.
This is our announcement to the media of the Concordia Program (everyone else pretty much already knows about it and we've been "announcing it" since February but this is our first Press Release).
I believe you understand what this is about (and you had the benefit of attending the Brussels meeting where we went into detail) so I'm hoping you can provide a statement of support.
Let me know if you can provide a quote... and please be mindful of the tight timeline (I'll need this nailed down by end-of-business tomorrow).
I've copied our PR lead who can follow-up with you and answer other questions you might have like "who else is being quoted" etc.
Thanks Doc,
?
---
Brett McDowell || office +1.413.662.2744 || mobile +1.413.652.1248
(please do not forward this (or blog this) without checking in with me first)
Doc,
I have been scratching my head about who to seek out from the "user-centric"/"grassroots" community for a quote in this press release. I have decided you are the best and most visible representative of that community. Therefore I would like to get a quote from you for inclusion in this press release that will hit the wire early next week.
This is our announcement to the media of the Concordia Program (everyone else pretty much already knows about it and we've been "announcing it" since February but this is our first Press Release). I believe you understand what this is about (and you had the benefit of attending the Brussels meeting where we went into detail) so I'm hoping you can provide a statement of support.
Let me know if you can provide a quote... and please be mindful of the tight timeline (I'll need this nailed down by end-of-business tomorrow).
I've copied our PR lead who can follow-up with you and answer other questions you might have like "who else is being quoted" etc.
Thanks Doc,