Sun releases standards-based Identity Server
Network World -
Sun Microsystems Inc. today released Sun ONE Identity Server 6.0, one of the first commercially available products to support two key standards for unifying user identity credentials.
The server features support for both Security Assertion Markup Language (SAML) 1.0 and the Liberty Alliance Project 1.0 specification. Both standards are designed to unify, or federate, disparate authentication software, allowing a user who is authenticated on Company A's network to be recognized as an authenticated user by Company B's network. Sun plans to support Liberty's new 1.1 specification by March.
While both specifications have generated a lot of interest for single sign-on capabilities across the Web, they are but two pieces of a complex puzzle. For example, a unified authorization technology is still needed, as well as a mechanism to establish trust among companies' authentication systems.
SAML and the Liberty 1.1 specification -- which incorporates the SAML specification and adds a set of usage policies -- help create user authentication and authorization information that's portable across corporate networks.
This sharing of user identity is referred to as federated identity management and is emerging as a key technology for distributed e-commerce and Web services. It lets companies more efficiently administer access to their networks and determine what resources are available to users. Identification information can also be used to personalize services and portal interfaces. The IDs can identify not just users, but also machines that need access to execute Web services in tandem with other machines.
Sun's Identity Server 6.0, which has been in beta testing since last summer, is a Web access management server, much like those from rivals Netegrity Inc. and Oblix Inc. The server is part of Sun's platform for identity management, which also includes its Directory Server, Meta Directory Server and Certificate Server. Identity Server 6.0 is bundled with Sun ONE Portal Server.
Sun says it's seeing interest in deploying this bundle of software from an enterprise level and not from a departmental level.
"We are seeing a trend of a top-down view of the business units, with this software used to secure those business units and to cut costs," said John Barco, senior product marketing manager for Sun Open Net Environment (ONE). "As companies using Identity Server 6.0 start to gain interest in a federated identity model to use with their partners, they will already have the software deployed."
Identity Server 6.0 ships with a set of 15 agents that control authentication to enterprise systems such as PeopleSoft, Lotus Domino, IBM WebSphere, BEA WebLogic and Apache Web Server.
The server includes a policy engine to support secure access using a set of rules stored in the directory. Access can also be controlled using a set of conditions including IP address, time, date and authentication level. In addition, authentication requirements can be set per resource. Administration of identities stored in the server can be delegated based on domain, roles, groups, applications or services.
Sun has also added support for Kerberos, Windows NT and 2000, the Java Authentication and Authorization Service, Lightweight Directory Access Protocol, Radius, X.509v3 certificates, SafeWord token cards and Unix platform authentication services.
Pricing for Identity Server 6.0 starts at $10 per user.
Reprinted with permission from
Story copyright 2009 Network World, Inc. All rights reserved.
Additional Resources


White Papers & Webcasts
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2008
This Research Report explores how vendors focused on solving enterprises' most-pressing application problems have become the top players....
Controlling Email and File Server Growth and Costs with Intelligent Archiving
(Source: Symantec) According to IDC 54% of the storage capacity added by organizations in 2008 will be dedicated to the storage of file-based...
Gartner Research Report: Load Balancers Are Dead - Time to Focus on Application Delivery
This research shifts the attention from basic load-balancing features to application delivery features to aid in the deployment and delivery of applications. Networking...
Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....
Speeding business innovation with HP Data Center Transformation solutions
Data center transformation enables your IT organization to focus more on business priorities and innovation by decreasing spending on maintenance and management by...
The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....
IDC White Paper: The Benefits of Datacenter Transformation with HP
IDC expects that for the next several years, there will be considerable investment in a datacenter "makeover: - not just in datacenter systems...
SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....
Get More! From Your Data Center: Rely on Liebert for System Availability and Integrity
Emerson Network Power and its Liebert power and cooling technologies can help you protect your applications downtime despite power outages or security threats...
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
Subscribe to Computerworld
