Showing posts with label ibm. Show all posts
Showing posts with label ibm. Show all posts

Friday, October 28, 2011

IBM Dropping Tivoli Brand from IAM Suite

I just read this story on Network World about IBM's plans to make Q1 Labs' Security Information and Event Management (SIEM) product, QRadar SIEM, one of the centrepieces of the newly formed IBM Security Systems division. IBM announced the acquisition of Q1 Labs and the formation of the new Security Systems division in the same press release earlier this month.

The news was a bit pedestrian until I read the following:
"IBM is dropping the 'Tivoli' name from the Identity and Access Management suite"
Of course, I did a double-take. As an ex-Tivoli-ean who went around spruiking the virtues of TIM and TAM, I was taken aback. To quote the great John McEnroe:
"YOU. CANNOT. BE SERIOUS!"
Years of goodwill (alright, and some bad when stuff didn't work the way we promised they would - but we always fixed it) and brand awareness thrown away. It also means people will no longer be able to deliver one of these Tim Tams to the customer as a joke instead of actual Identity & Access Management software.

IBM Identity Manager and IBM Access Manager just don't have the same ring. The resulting acronyms are harder to pronounce, and downright confusing, respectively. IIM and IAM. Go around talking about "IIM" and people will think you missed a word and uttered something random in place of said missing word. Either that or they'll ask if you have something stuck in your throat and whether you'd like some water. Talk about "IAM" and people in security will assume you are talking about "Identity & Access Management", not "IBM Access Manager", which only partially fulfils the "AM" part of the real IAM.

This "IIM" and "IAM" talk presents a decent enough segue to the fact that the acronym for IBM's new Security Systems division is "ISS", as opposed to Internet Security Systems (ISS), whom IBM acquired over 5 years ago and then re-branded IBM Internet Security Systems (IBM ISS). The old ISS (Internet Security Systems) technology is no doubt going to be rolled into the new ISS (IBM Security Systems) along with the IAM (Identity & Access Management, not IBM Access Manager) suite that is no longer Tivoli and the Q1 Labs technology.

At this point, you may want to take a break. Your brain must be hurting from that last paragraph...

And, we're back.

While we're on confusing branding, which IBM is no doubt very good at, I'll take this time to note something else IBM is also very good at: bad product names. IBM recently released an add-on to Tivoli, oops, I mean IBM Identity Manager, called Role and Policy Modeler (RaPM). Gees, IBM. Why didn't you just call it "Role and Policy Enforcement Modeler"? I'll leave it to the reader to work that acronym out.

So, IBM, seriously...WTF?

Alas, it is with some sadness that I must now bid adieu to "TIM TAM" and welcome, rather begrudgingly, "IIM IAM". I just said that out loud. Must. Wash. Mouth. Out.

Thursday, September 16, 2010

IBM just became a serious GRC player

IBM just announced that they are acquiring OpenPages and it will become part of their Business Analytics and Optimization division (which came into being because they acquired Cognos and SPSS some time ago and have since added Coremetrics and Unica to). For those who are unaware, OpenPages is a serious player in the Enterprise GRC space.

I'm not planning on analysing this to the nth degree because I'm not an expert on Business Intelligence (or Analytics as IBM calls it), but I do know a little something about Governance, Risk and Compliance (GRC).

As I mentioned previously, OpenPages is actually an Enterprise GRC vendor. That is, their focus is more on business and financial risk/compliance. If you're still confused, think Basel II (soon to be Basel III) rather than COBIT.

It makes sense for them to roll OpenPages into the Business Analytics group. But this also means that it is unlikely that the other software brands will get to have very much to do with it. I'm naturally thinking about my old mates from Tivoli here.

That said, there's actually only a very thin, dotted line that can be drawn from OpenPages to Tivoli. To make that dotted line a solid one, IBM needs to add another piece to their arsenal: IT GRC, specifically the type that links GRC to Identity and Access Management.

I'm almost certain that there are a few IT GRC (especially the Identity-centric ones) vendors that IBM Tivoli has their eye on. It's only a matter of time before they acquire one for my old mates to sell. I wonder if the relevant product teams at Oracle and CA (whom I've spoken to in the past) are sitting up a little straighter at their desks today (side note: if anyone at CA is listening, it was REALLY difficult to find a link to CA GRC Manager from your website - I almost wondered if you discontinued it).

Wednesday, November 11, 2009

IBM Redbooks rock

Many of my former IBM colleagues/friends like to bring up the fact that I'm rarely nice to IBM on this blog. They're right, but it's because I hold IBM up to high standards. When they don't deliver, I make it a point to voice my opinion. For example, I have no idea what the brains trust in the IBM Tivoli Security group over in Austin have been doing for the past few years but your products have stagnated. And the new ones you bring out aren't particularly exciting. It's disappointing to say this, but IBM are losing ground (falling behind if you listen to Forrester) in the Identity & Access Management stakes to Oracle and CA. Wake up product management team!

One of the BEST things out of IBM however, are their Redbooks. These are essentially step-by-step guides for implementing IBM technology with lots of background information thrown in and fictitious "real-world" scenarios. Not many people realise IBM publishes these books but they're great if you're doing anything with IBM software or hardware (and in many cases, even when you're not).

I'm bringing this up because I noticed they released the latest Identity Management Design Guide, which leverages Tivoli Identity Manager 5.1 a few days ago (the one I co-authored 2 iterations back was for version 4.5.1). It's a little thicker (i.e. it has more pages) than the version of the book I was involved with, but in looking through this latest version one thing stood out: I still recognise most of the content, especially the parts I wrote. It's nice to see the content is being leveraged in subsequent versions. What that means is that the materials produced with each iteration are solid and practical, which is true for pretty much all the Redbooks that get released.

In short, Redbooks are a great resource for:
1) People who want to learn about an IBM product or a subject area.
2) People who want to implement the relevant IBM product.
3) Competitors who want to take a detailed peek at an IBM product ;-)

I'm sorry IBMers, but I couldn't resist taking a stab at IBM Tivoli Security. The Redbooks however, remain one of the best things out of IBM. They are infinitely better than those marketing data sheets we've all wasted time reading.

Wednesday, October 21, 2009

My first identity and access management project

In a previous post (which I subsequently followed up with another), I mentioned the first Identity and Access Management (IAM) project I worked on. I also said I'd follow that post up with more details about the project I mentioned. It's been some time since I said that, but I've finally gotten around to it.

My very first IAM project was an extremely large one. It was for one of the larger Australian federal government agencies and I can't give specifics (or they'll hunt me down) so forgive me if I'm vague in certain parts.

They needed to re-engineer a core, critical business process from end-to-end. This meant a brand new system needed to be built and it ended up taking years. I personally spent almost 2 years early in my IBM career working on this monster as a consultant in the Security and Privacy practice and when I finished serving my time there (reference to prison completely intentional), they were still rolling out other functionality.

My job was done however, because we had finished laying down the whole security framework and it was working in production. The security system was actually very well architected thanks to the fact that it was designed by a very senior, very experienced, absolutely world class enterprise security architect (hi BP, I'm referring to you if you're reading this - probably not though so one of you other IBMers will have to tell him I said hi). This was actually the key. We could have slotted any equivalent product into the architecture and it would have served its purpose. Of course, being strategically aligned with IBM Tivoli meant this was what we used.

The project used a bunch of IBM software: WebSphere Application Server, MQ Series, DB2, some other IBM software to support EDI transactions (can't remember the names anymore) and of course IBM Tivoli Security software (specifically Tivoli Access Manager for e-business and Tivoli Directory Server). We even had full blown PKI software (from another vendor) to support signing of messages (for authentication purposes) and encryption. At the core of this mish-mash of software wrapped with services (provided by a consortium that was not limited to IBM alone) was Tivoli Access Manager for e-business (TAMeb). And what was its primary use? Fine-grained access management or as some of the market likes to call it today; entitlement management.

That's right, I was responsible for implementing fine-grained access/entitlement management in very first IAM project but I didn't know it at the time. Absolutely everything had to ask TAMeb before it could do anything. Want to show a button on a page? Ask TAMeb. Want to show a field on a page? Ask TAMeb. Want to allow someone to process a particular transaction? Ask TAMeb. Can this application send this message to this other application where the message is marked as secret and does it need to be encrypted as well? Ask TAMeb. No application security decisions were made without first making an authorisation call to TAMeb. None of this stuff involved web access management! Sure, we had to implement the web access management aspects too, but this was not the focus. We put in the web access management bits because it was mandated by the security architecture. But this was by no means a web access management project.

From an ease of development, time, manageability and subsequently cost standpoint, having all access control decisions managed centrally made perfect sense. I'm pretty sure everyone on that project would agree with me on this point. Here are a few reasons why they liked having a central access management point:
  • All teams could adhere to the same interface contracts when it came to authentication and authorisation. This also meant that if a development team couldn't get a security component working and everyone else could, it was their fault and usually could get it fixed fairly quickly because others knew how to do it properly.
  • No one had to write their own security sub-system because it was already sitting there waiting to be used and it worked extremely well. This meant they could spend time worrying about the more interesting things like business logic. I have yet to find a developer who likes writing security code (unless they are building a security product and even then it's debatable whether they actually like what they are doing) because it's simply a hurdle to getting the "real work" done.
  • Teams could re-use existing policies if required because they were mostly modelled on a business requirement.
  • No need to worry about policy modelling or management of security policies.
  • If a policy changed, it would be reflected across all systems. Without a central store, they would each need to worry about how to synchronise their policies so that there weren't any back doors to exploit. This alone is a whole sub-project on its own.
  • Security within each system was distilled down to a single statement: "Ask TAMeb". Compare this with having to worry about designing and building a security sub-system, designing and building a way to model identities, roles, policies, resources within the sub-system, designing and building a management layer on top of the sub-system and then worrying about how to ask the sub-system to make decisions from the main application. I'm talking best case scenario here of course because quite often, development teams simply use configuration files which are completely unmanageable (if you've ever written a Java Enterprise application and played with crappy deployment descriptors, you know what I mean). And if you understand the implications of using config files, you'll know that each time a security change is made you have to restart the application (which is going to screw with your SLAs) unless your vendor has some fancy way of dynamically updating in-memory application configuration settings. Oh, I haven't yet thought about how to synchronise security policies with the other systems floating around. Manually you say? Or use a provisioning product? Yeah it's possible. But it also means a heck of a lot more design and analysis work (in the case of the provisioning product). If you want to do it all manually, you can expect to have very frequent security incidents and lots of follow-up meetings with management to explain why it happened.

One of the biggest challenges was the huge number of transactions (and as a result, access control decisions) passing through the system due to the sheer size of the project. And to the credit of TAMeb, it scaled well and did the job. Of course, we had to do proper capacity planning and implemented multiple enforcement and decision points (PEPs and PDPs in the XACML world). And the Policy Administration Point (PAP)? This was a combination of the TAM administration console and an application we had to build to perform "identity management". Why did we have to build this? Because IBM hadn't acquired Access360 yet (which became Tivoli Identity Manager) and the existing IBM provisioning product was a piece of crap called Tivoli Identity Director which still relied on the Tivoli Framework (those with experience playing with the old framework know it's EXTREMELY painful).

I should explain why we had to build an "identity management" component on top of TAM. One major criticism of TAM when it comes to fine-grained access management is that it's not very good when you need to add a bit of context that relies on user attributes because:
  1. The admin console doesn't give you access to them (last time I checked). To play around with user attributes, you either need to access the LDAP directly or use a provisioning product like Tivoli Identity Manager.
  2. Contextual access control decisions based on user attributes are also not the easiest to model without a provisioning product to help. In short, you need to do it based on dynamic role memberships and have policies on resources (or entitlements) tied to these roles. Provisioning products can do this (cater for dynamic roles based on user attributes) out of the box and provision the required changes to the access management product in near real time.
In other words, we had to build the "identity management" piece to allow for contextual access control decisions based on user attributes. Nowadays of course, you can just use your favourite provisioning product.

The glaring omission from the picture is of course XACML. It wasn't even part of the IAM vocabulary at the time and the lack of XACML support in the project makes it very difficult for the government agency to swap TAMeb out of the picture (which IBM definitely isn't complaining about). But I'm guessing it's not a big deal for them because they spent a few million shed-loads worth of tax-payer's dollars to build this system and it works as designed. They're not about to replace the critical security component that makes all the decisions!

The motivation behind my occasional rants about the term "entitlement management" and how it's all too often used as a marketing gimmick to sell more products stems from my time on this project.

Broken record time: call your vendor out if they're blatantly repackaging fine-grained access management as "shiny-new-entitlement-management". If it's more along the lines of what the Burton Group thinks it should mean, we might start to get somewhere. It's still a moving target however, so I'm sure the definition will expand and evolve, especially with all this Cloud crap floating around.

Thursday, March 19, 2009

What does an IBM acquisition of Sun mean for Identity Management?

IBM employees: hands up those of you expecting to tell management to stick their redundancy packages where "the Sun don't shine"?

Sun employees: hands up those of you who walked into a meeting this morning and came out to be greeted by people with spray cans and paint tins eager to paint you IBM-blue, itching to call you a smurf?

In case you've been in a cave today, the rumour ("rumor" for my American friends) doing the rounds is that IBM is in talks to acquire Sun. I should stress that is a rumour, but I suppose everyone thinks the fact that the Wall Street Journal is one of the news outlets reporting on this rumour gives it some additional weight.

I wasn't going to bother writing anything given that nothing has actually happened and I'm not sure how this is a no-brainer move for IBM, but a few people have emailed asking what I think. So the easiest way to respond was to post this.

There's no shortage of coverage across news outlets, blogs and in Twitterville. Everyone's talking about the big picture. Larry Dignan (thinks it makes sense) and Dana Gardner (doesn't think it makes sense) have more insightful commentary than most stories I've read. Commentators generally mention data centers, servers (i.e. hardware), cloud computing, professional services, Java, IDEs (NetBeans vs. Eclipse - consensus opinion seems to think NetBeans will go the way of the Dodo), Unix (AIX vs. Solaris) and open source. Many of them are saying that it makes sense in a macro-company kind of way. I however, will be focusing on a specific something else where I don't think it makes any sense at all. Then again, in the grander scheme of things there's usually some sort of sacrifice when these things happen, especially today when the flavour of the microsecond is all things cloud-related and not un-sexy-enterprise-off-the-shelf-run-it-in-your-own-data-center software.

My point is that very few reports have touched on something that should be on your mind if you work in enterprise software: what's going to happen to the software stack? There are overlaps EVERYWHERE! There are too many products to talk about in detail but IBM cannot simply throw Sun's stack away because of the backlash they're going to get from customers and the community at large.

If IBM does acquire Sun, they sure as heck aren't doing it for the software (except for perhaps additional "control" over Java). And they sure as hell aren't doing it because Tivoli's run out of role management vendors to acquire and liked VAAU (which became Sun Role Manager) so much they went to Sam Palmisano and told him to buy Sun as punishment for getting to VAAU before them. Does this mean they'll just throw Sun's software division away? Of course not! That would be stupid on IBM's part (and despite what I've written about in the past, I don't think IBM are stupid). They will more than likely run everything separately initially, figure out what bits and pieces fill missing holes in the IBM software portfolio and then "blue-rinse" (rebrand) them. The overlapping pieces will be absorbed into the IBM blue-ether and have useful components re-used within existing IBM software and the perceived useless bits discarded. It's IBM's modus operandi (just look at what they did with their DB2-related acquisitions). It's also what Oracle does, so at least someone else thinks it makes sense.

And here's where I'm going to head down the rabbit hole, because this is all based on a rumour. In other words, it's speculation and anything said is simply mental masturbation.

The least affected IBM software brand will be Lotus. Rational should be relatively unscathed. The other three IBM software brands (Tivoli, WebSphere, Information Management aka DB2) however, will notice a few changes. None will be affected more than WebSphere, but Tivoli comes a close second in the upheaval stakes. This is where the IBM's Identity and Access Management (IAM) suite sits, which is what I'm going to focus on now.

The first win for IBM will be in the marketing stakes. I don't mean this in terms of positive karma or PR, but more in terms of the marketing talent at Sun. This is because Sun has been better at marketing, community building and listening to customers than IBM has within the IAM space. Now, assuming IBM doesn't fire the whole IAM marketing team they'll be inheriting a very strong team of people (yeah I know their engineers aren't too shabby either). In my opinion, Sun understood the evolution in marketing that's been occurring much earlier than IBM and hence are ahead in the game from this standpoint. Actually, pretty much every other big IAM vendor understood this before IBM. In IBM's defence, they are starting to pick up their game and are running with it wholeheartedly.

On to the products. I thought of doing a full comparison by listing each company's full list of IAM products, but then I started writing down IBM's list from the website (in case I missed anything by relying on my memory) and it gave me a headache (Side note to IBM: WTF?! The list has gotten much more complicated and longer. And to add to the confusion, you even list "products" that are actually solutions made from combining different underlying products. If you are able to give an ex-employee who used to architect, implement and sell this stuff for you a headache when going to your website, what do you think customers are going to think? Or maybe I just don't have the mental capacity to read introductory product information about IBM software). Conversely, Sun's list is much easier to follow (although whoever runs the website should probably place Access Manager and Federation Manager in a separate list noting that they've been combined to form OpenSSO). Here's the core Sun IAM list with commentary:
  • Sun Directory Server - IBM has Tivoli Directory Server.
  • Sun Identity Compliance Manager - IBM does not have a direct equivalent.
  • Sun Identity Manager - IBM has Tivoli Identity Manager.
  • Sun OpenSSO Enterprise - IBM has Tivoli Federated Identity Manager and Tivoli Access Manager for e-business (which is actually used as a component within the Federated Identity Manager product, but I won't complicate things here).
  • Sun Role Manager - IBM does not have a direct equivalent.
Thanks to Sun's simpler list, there's a relatively clear picture to work with. I should note that IBM has quite a few more IAM products that I've listed (IBM lists them as part of the Security Management suite), but I'll ignore them because a potential acquisition of Sun should not affect them too much.

What's abundantly clear here is that Sun Role Manager and Sun Identity Compliance Manager (don't confuse this with Tivoli Compliance Insight Manager because the IBM product addresses different requirements) look to be safe from the chopping block. IBM will simply take the 2 products (aside: my understanding is that Compliance Manager is actually derived from Role Manager - Sun people, please correct me if I'm wrong) and "blue-rinse" them. Their names will likely stay the same with "Sun" being replaced with "IBM Tivoli". Either that or IBM will combine them and call it "Tivoli Identity, Access and Role Compliance Manager" or some long-a**ed name that forms yet another T-acronym. At least you can kind of pronounce TIARCM, albeit getting tongue twisted in the process.

As for the other Sun IAM products, their futures are at risk if this rumour proves to be true. IBM's spent shed-loads of money acquiring, "blue-rinsing" and subsequently developing their equivalent products. It's VERY unlikely that IBM will throw that investment away only to repeat the exercise again with Sun's stack. In other words, I have a feeling that in the longer term, Sun Directory Server, Sun Identity Manager and Sun OpenSSO Enterprise are seriously in danger of being "sunsetted" (yeah, I cringed too when I typed it). Interestingly enough, many people are of the opinion that Sun's Identity Manager is a superior product to Tivoli Identity Manager. Conversely, the reverse is true when comparing Federation/Access Management products. Opinions such as these are of course subjective and depend on the requirements at hand and people's personal preferences. The truth is that they are all pretty solid, mature products in their own right so there's no easy answer in making a decision to pick Sun's version over IBM's or vice versa. I see 3 logical possibilities here:
  1. IBM "sunsets" the relevant overlapping Sun IAM products, which will mean that they'll continue to support existing customers but gradually migrate them over to the Tivoli versions.
  2. IBM markets the Sun IAM products as open source alternatives to their enterprise incarnations.
  3. IBM re-hashes the rather unsuccessful "Express" line of products.
Option 1 will be the least popular alternative in the eyes of customers. But it means BIG services opportunities for IBM and IBM's channel of business partners which provide consulting/implementation services. From an IBM perspective, they would be making the sacrifice early on for the greater good of the company and taking the PR and initial professional services (in having to give away free services for the migration to prevent angry mobs from gathering) hit that comes with it (like they had to do when they acquired Encentuate). This is the "rip the band aid off quickly" approach, but it also means lots of job cuts with the sales and marketing teams being first out the door.

Option 2 is the easy way out, but is also the most expensive. Sun already markets their product line as being open. The heavy-lifting part of the marketing's been done and all IBM has to do is see it through while changing the product names. Unfortunately, this is expensive from an ongoing operational and development standpoint. They may choose to absorb the cost as a "good karma tax", so this option could very well fly. The upheaval to existing Sun teams and customers would also be mitigated. This is the "don't rock the boat" option.

Option 3 is the "marketing blue-rinse" option. It's more or less a hybrid approach of options 1 and 2. IBM will be looking to cut the fat somewhat from a jobs perspective, but not as drastically as they would if they went with option 1. From a technical standpoint, this will be very similar to option 2. The difference is that they bring the products back in-house and promote them as the "light IAM options" for small to medium business. This was exactly the target market for their Express initiative and they may look to re-energise those efforts . Ironically, Tivoli Identity Manager Express was a response to the market perception that Sun Identity Manager is easier to deploy and manage. If this happens, I don't think the Sun products will survive beyond a year or 2. IBM's Express experiment has proven that customers that buy Tivoli still like to choose the heavier version "in case" they need the features and perceived superior stability. Remember, this is not to say the Sun products aren't stable or fully featured. I'm just saying that in this instance, that's what the marketing materials are going to imply and how the sales teams will be selling the products. If not, IBM would look pretty stupid for continuing development on 2 equally good products in parallel that serve the exact same purpose (in the eyes of the customer). If "Express" doesn't sell, this option is simply the less painful, more drawn out, more expensive version of option 1.

No matter which option IBM picks, one thing is certain. They're going to run a fine-tooth comb over the Sun product set, pilfer all the useful bits and roll them in to the existing Tivoli product set. This is good for Tivoli customers but it'll take time for the functionality to start appearing given the speed that IBM moves at.

I don't think competitors like Oracle, CA and Novell will be quaking in their boots though. From an IAM standpoint, any acquisition only increases IBM's market share. It doesn't really give them a big advantage when it comes to product features or functionality. Then again, significantly increased market share is nothing to be sneezed at.

If the rumour proves to be based on solid information and something does happen, the real winners (other than IBM) will be existing IBM customers. The biggest losers? Existing Sun employees and customers, at least from a software perspective.

Friday, March 13, 2009

IBM gets more end-pointy

To be specific, I should say IBM ISS. This time, they're getting in bed with with BigFix (the press release is here). Here's the first paragraph of the release:
"Today, IBM announced a first-of-a-kind endpoint security offering, IBM Proventia Endpoint Secure Control (ESC), that is designed to enable enterprises to escape from the constraints of vendor lock-in and to enhance endpoint security, compliance and operations at a lower cost. This new endpoint security offering is delivered by IBM Internet Security Systems (IBM ISS) leveraging IBM's depth in security experience and technology from BigFix, Inc. for endpoint security management."

It sounds like it's some sort of OEM agreement with BigFix to offer up security-focused, endpoint systems management. Essentially, it's to allow for organisations to manage all the bits and bobs of software that end up having to be deployed on endpoints (laptops, desktops etc.) and become a nightmare to manage over time. IBM harps on about "vendor lock-in" and stress that having ESC/BigFix in place makes it much easier to swap out software and replace it with new stuff (McAfee AV with Symantec's, for example). Sounds nice in theory and marketing slides. Not so simple in reality, even with a shiny new toy.

I won't get into the minefield relating to it being a good idea to have some sort of common security policy management or decision point across everything (which is what Symantec and McAfee are trying to do across their bag of toys) that this doesn't address, but I'm sure IBM are working on that. By the way IBM ISS, the boys at Tivoli might have some stuff that you could use? You should try talking to them...which brings me to my next point.

I can't help but notice that there's some level of overlap with what IBM Tivoli provides in the way of their systems management software, but this is IBM so it doesn't surprise me that the left hand doesn't seem to be talking to the right hand. It's business as usual and somewhere within IBM, a bunch of people in Tivoli are going to be wondering why IBM ISS keeps trying to compete with them. To be fair, the IBM Tivoli stuff isn't as endpoint-focused when it comes to security and isn't as security-focused when it comes to endpoints (this is confusing unless you know the Tivoli products - you IBM Tivoli people know what I'm talking about don't you). The press release does make a reference to Tivoli:
"The new tool will complement IBM Tivoli's operational desktop management offerings with robust endpoint operational security solutions, allowing customers the ability to address end point security. IBM Proventia ESC will also provide key endpoint security audit data to IBM Tivoli Security Information and Event Manager (TSIEM), further strengthening TSIEM's enterprise-wide compliance reporting capabilities."
But that statement sounds to me like it was thrown in to "keep Tivoli happy". TSIEM could get its endpoint security audit data from any other competitive endpoint source. It doesn't need ESC specifically! Of course, the marketing department will throw in comments like it'll be better integrated and have "out of the box connectors" but we know how true these things are. Unless development is managed by the same brand, this is extremely difficult to achieve in an adequate amount of time. My money's on the fact that the implementation partner is going to have to be the one that picks up the pieces if/when the integration at a client's site is required.

Strategically however, this move makes sense. If your memories go back to late 2007 (yeah I know that's quite some time ago), you may remember IBM ISS dipping its toe into data security by offering managed services using a combination of Verdasys, Fidelis and PGP software. I'm not sure they got very much traction out of that initiative, but this is a continuation of an increasing focus on the endpoint by IBM ISS, and they want to manage it all too:
"'The killer application in endpoint security is management,' said Dan Powers, vice president of business development at IBM Internet Security Systems."
I don't really agree that management is "the killer app" in the endpoint game, but it's certainly a key piece. The likes of Sophos, Symantec, McAfee, Checkpoint have all been progressively coming out with their own versions of "one agent to rule them all" and wrapping a management layer around it all. I suppose IBM ISS didn't want to get left behind because when it comes to data security, if you ignore the endpoint you've lost the game.

Monday, March 02, 2009

Did IBM actually listen to me?

Or was it a coincidence? I'm not sure because I never did hear back from anyone within IBM in response to my open letter.

The letter I speak of was a rant where I openly asked IBM why they thought it was appropriate to list member email addresses on their newly created communities site by default and not allow for an opt-out. What they really should have done was to set all details as private by default and allow people to opt-in with regards to their details being made public. The fact there was not even an opt-out in relation to email addresses being displayed was unacceptable in my opinion.

I've been away for the past week snowboarding in the French Alps (I just had to throw that bit of detail in - curse me if you must) so I've been a little bit out of it. In trying to "plug" myself back into society, I decided to have a look at the IBM communities site for a laugh. I even contemplated posting my rant to the forum due to their lack of any response. But to my surprise, I noticed something different: email addresses are no longer displayed!

I don't seem to see any changes in being able to set privacy controls, so the interface is exactly the same. But some educated individual's either decided that public emails were a bad idea or they read my rant and did something about it. Makes you all warm and fuzzy doesn't it.

In other news, I'm still getting a shed-load of spam to the email address that IBM made public. Thanks IBM.

Wednesday, February 11, 2009

Open letter to IBM - your communities sites are causing spam

Dear IBM Community Managers & Social Media Czars,

I've noticed that you have finally realised it's 2009 and not 1989. As such, you seem to have taken little baby steps moving beyond traditional methods for marketing and community building. Apart from a sporadic sprinkling of twitter accounts (mine is here if you want to follow me to deal with my complaints there instead of waiting for open letters), you now seem to have what looks to be the beginnings of centralised communities sites (whoa what an "innovative" concept).

It looks to me like these sites are trying to aggregate useful things for each community (e.g. blogs, tags, forum discussions) and while not exactly "cutting edge" is a start considering how you have done nothing about evolving your old marketing and communication strategies since Lou Gerstner joined the company. He obviously couldn't do much about it because he was too busy trying to save IBM from going down the crap hole, so you could be forgiven for taking some time to catch up but seriously, it's frigging 2009 IBM.

I have a specific issue regarding your communities sites. Maybe I'm stupid so bear with me but I signed up to be a member of your IBM Security Community thinking I should take a look at whether my ex-employer has finally realised what year it is. The first thing it insisted on was that I used my IBM ID (which still thinks "Identity Federation" might have something to do with Star Trek). This is fine, except that the IBM ID now insists that users have to use their email address as their login. This is fine in principle, but it looks to be the root cause of the problem which I will expand on later. All things considered, this part of the process was fairly easy. So I started to take a look around and realised that it was pretty bare-bones. Again this is fine because I realise this whole "Internets tubes thingy with sites and people at the end of them tubes" is fairly new to you.

Just a matter of days later, I started to get messages sent to my personal email offering to shower me in riches on receipt of my bank details and interesting products offering to "enhance my manhood". I NEVER used to receive unsolicited messages to the email address in question due to the fact I take precautions not to give it out unnecessarily or to post it online (yes on the "Internets tubes thingy"). So I did some digging online (it's called searching, IBM - you may have heard of this small company called Google?) and found my email address! And where did I find it?! On your IBM Security Community site that's where! I should note that I could see this without being logged in. Yes, this means it's PUBLIC.

I immediately logged in and tried to find the offending page. Upon finding it, I immediately went about trying to change my settings to remove it from public view. About 15 minutes later, I finally realised I had to navigate to a listing of everyone's profiles to get to my own profile (nice to see you still haven't hired usability designers). I then clicked on my profile details and there it was, my email address staring at me.

While the incongruity of it all was unnerving, I pressed on. I thought: "OK, I've found it, now I'll just go change the settings". So, I clicked on "Edit My Profile" and spent about 10 minutes clicking on the same links over and over and over and over and over again in the hope that my email address would magically appear (that's what I used to do when I had to demo your software). I persevered thinking that it must have been my own fault or stupidity. And then I had a "eureka moment" as I glanced at the bottom of the screen. It read; "IBM Lotus Connections". And then it hit me: "Ohhhhhh it's Lotus software. I'm going to need to go screw around with some Lotus Notes database somewhere which I don't have access to". By the way, is this new-fangled Lotus software incarnation just crappy old Lotus Notes with web bits hidden behind WebSphere Portal Server (if you mention the word "cloud" anywhere in your answer I'm going to throw up)?

IBM, does this mean that you are simply pulling my email address from my IBM ID and not giving me a way of changing this? Why does this matter you ask? Well, perhaps if it was listed I could potentially delete the field in the absence of adequate privacy controls in your software. That's why! But the fact it's linked makes me think that I'd have to de-provision my IBM ID, or at the very least de-provision my IBM Security Community membership (is that some Lotus Notes group?). Oh I'm sorry I just realised that I'm talking to Lotus and you don't talk to Tivoli so all this talk of provisioning must be confusing the heck out of you. Don't despair, read on and you might start to get it.

Thinking that surely this could not be the case for everyone unfortunate enough to have signed up to the IBM Security Community, I looked around. Surely enough, I found a link that listed ALL the members of the community. And against each member was...you guessed it: their email address. Don't tell me it's all fine because to get the email address you have to hover over the person's name before the menu comes up to click through to their details. A bit of JavaScript cobbled together with "security by obscurity" does not pass the test. At this point, I was thinking that this was pretty piss-poor (Aussie slang but I think you get the point) given this was supposed to be the frigging "SECURITY COMMUNITY".

Hoping that this was isolated to this community, I decided to take a look at the other non-security communities. I hoped that someone would have some sense to configure the other communities differently. To my despair, the other communities were exactly the same which made me think this was the default behaviour of the software. So IBM, this is what you've done; anyone who is a member of one of your new communities sites has now had their email address exposed to the world whether they like it or not. Even worse, there is no way to turn this off short of leaving the community. But it doesn't really matter now because you may not have figured this out yet IBM, but once something is on the web it's pretty much there forever. So I could leave your community, but the damage is already done so there's not much point.

I'm not actually sure your community moderators can do much about this issue so I choose not to blame them. It is disappointing that it looks like this is the default behaviour of your "Lotus Connections" software.

Having tried unsuccessfully to change my profile settings, targeted twittering to ask this question (without replies) and a lack of an obvious mechanism for feedback on the communities site, I've decided to write this open letter hoping that someone at IBM who can do something about it reads this. If this has reached somebody in Lotus-land, you are probably confused by all this talk of security and privacy. In the event you have not spoken to someone in Tivoli-land to help you decipher my ramblings, I'll summarise everything for you:
Why do all the IBM communities sites display all member email addresses by default? This would not be so bad if there was a way to update profile settings to hide email addresses. But either through a software limitation or my own stupidity, there does not seem to be a way to do it. Why does IBM see fit to display people's email addresses by default and not allow for a way to "opt-out"?

By the way IBM, if I were to "accidentally" click on one of these offers I'm getting in my email, can I use my old IBM expense account to claim the costs? If so, I could potentially overlook your blatant disregard for my privacy.

Yours sincerely,
Ian Yip
Disgruntled ex-IBMer

Friday, October 03, 2008

IBM tries to rain on Novell and HP's parade

The cynic in me is crying out for this blog post, so here I go.

It's not that I enjoy pointing out my ex-employer's boneheaded moves, but...ok so I do just a little bit.

IBM issued a press release today harping on about:
"migration services and competitive migration pricing for abandoned HP Identity Center security software customers aimed at helping them benefit from IBM's broad capabilities for securing and efficiently running IT for their business."
For those that don't remember, HP got out of the Identity Management software business earlier this year and left their existing customers with a bit of a problem. Then along came Novell on their horse offering to ease the pain in partnership with HP.

From what I can gather by reading the Novell and HP partnership press release, existing customers get equivalent Novell Identity Management software for free (until the middle of 2009) and some migration tools jointly developed by HP and Novell. There is no mention of free services however, so I assume there's some cost there.

I didn't see the word "free" anywhere within IBM's announcement. So my question is, are they going to guarantee that the combined software and services costs are going to be less than Novell's? If not then what the heck is the point of offering to "Bail Out HP Security Software Customers" (part of the press release's headline)?

Oh, it gets better:
"In response to HP's discontinued identity management products, IBM offers competitive migration pricing for software and migration services through IBM Internet Security Systems (ISS)..."
Notice the problem? IBM ISS specialise in network security! Talk about picking the wrong business unit to offer up as the service provider. It would have made a bit more sense if they had said IBM Security and Privacy Services (which was the division I worked for before doing my IBM Tivoli thing) or IBM Software Group Services (who used to try to bill me out to customers because I knew stuff, even though I worked for the IBM Tivoli technical sales team - management usually said no by the way, except for a few times I had to run customer training sessions because they supposedly "asked for me by name"). Both these business units have had years more experience deploying the Tivoli Security suite of products. They also have a heck of a lot more people that have the necessary skills to do the work.

Here's a few speculative reasons why they might have made this announcement:
  1. To piss Novell off a little bit and also hopefully catch all the existing HP customers that don't like Novell for some reason. Of course, there's nothing stopping customers from going to Oracle, CA or Sun. I dare say they'd willingly give existing HP customers "competitive pricing", which by the way means nothing becase it's not quantifiable.
  2. A boneheaded IBM ISS executive was trying to figure out how to increase ISS revenue and decided on this particular tactic.
  3. A boneheaded IBM executive was trying to figure out how to increase IBM revenue and decided on this particular tactic. The executive then thought that since it was security related, they would use the ISS business unit to deliver the solution because "hey, we acquired them 2 years ago as one of the world leaders in providing security solutions right?"
I wonder if the other consulting and services business units within IBM knew about this before the press release. My guess is not, but all you IBMers out there can correct me if I'm wrong. And if I'm right, there's going to be a few IBMers walking around today asking the same question and wondering why IBM has once again decided to compete with themselves.

This ISS rant assumes one thing of course, and that is that they actually find customers who want to switch from HP's Identity products to IBM Tivoli at a potentially higher monetary cost. I've already said I don't really see the financial value (I won't argue all the other bits because I'm trained to argue IBM Tivoli business value in my sleep).

In short, all of you working for ISS can just go about your business as if none of this ever happened. Well, all except the sales people who I'm sure will be told that they now have a new "innovative offering" to be peddling.

In other news buried within the same press release (I don't know why IBM keeps mashing multiple bits of news into the same press release), they announced:
"IBM Tivoli Security Policy Manager -- Brand new IBM software that provides customers the ability to develop centralized security policy management for managing application entitlements driven by compliance, data security and intellectual property protection. The adoption of SOA and Web 2.0 technologies poses unique security policy management challenges for managing user entitlements -- the loose coupling of services and mash-up applications across a business creates multiple policy management points, each of which may require its own administration. The IT reality to manage these policies and entitlements in an environment full of different vendors' technology is manual, error-prone and creates costly islands of security administration. Tivoli Security Policy Manager, available by end of 2008, provides standards-based, centralized application entitlement and SOA security policy management capabilities to help users strengthen access to new applications and services and improve policy compliance and operational governance."

Are you back from your eyes glazing over yet? Let me cut to the chase for you: the long marketing blurb basically means IBM Tivoli are releasing their Entitlement Management product later this year. I've seen it in action but am not at liberty to say anything at this stage thanks to the NDA. That said, it's probably not fair for me to be commenting anyway because I've only seen the Beta version, not the fully-fledged "we've tested the crap out of it and made it all nice and pretty" version. Well, maybe not the "nice and pretty" bit. If you've seen IBM software interfaces, they are rarely "nice and pretty". But I'm biased because I use a Macbook Pro as my personal computer :-)

If you work for IBM ISS, feel free to send any hate mail my way...

Friday, September 05, 2008

Encentuate blue rinsed

One of IBM's press releases today announces that IDC has named them as the "Overall Leader in Worldwide Identity and Access Management Software".

Frankly, I don't care. Each analyst has a favourite and if you make your purchasing decisions solely based on what your favourite analyst says, you need to have your head examined (yes I know software vendors care about this - remember that I used to have to stand up in front of people and point at slides showing how much selected analysts loved IBM Tivoli). IBM just happens to be IDC's favourite in the Identity and Access Management software market.

I bring this up because buried within the press release is a sub-announcement of sorts:
"IBM also today announced the availability of new IBM Tivoli Access Manager for Enterprise Single Sign-On software, redesigned based on technology from IBM's March 2008 Encentuate, Inc. acquisition."

In other words, IBM have finished "blue rinsing" Encentuate's product which they acquired earlier this year (read what I had to say about the saga here, here, here, here and here).

Interestingly enough, I can't seem to find a separate press release announcing the new version of IBM Tivoli Access Manager for Enterprise Single Sign-On so I'm wondering if they let the cat out of the bag a little early. That said, the product documentation is available so maybe not.

The press release also mentions that:
"Portland General Electric, Oregon's largest electric utility, uses IBM Tivoli Access Manager for Enterprise Single Sign-On and plans to upgrade to the new version 8.0 as part of its security technology strategy to help the utility company drive productivity and save costs on IT and help desk support. The effort has simplified password management for employees, who otherwise could have more than a dozen passwords to access over 20 different enterprise applications."
Two things:
  1. Version 8.0?! Did they skip a whole version number? The latest version (up until this point) was version 6.0. What happened to version 7.0? In fact, IBM were quoted as saying version 7.0 would be the first incarnation of the Encentuate product re-badged as IBM Tivoli. So I'm a little confused. It's not a misprint (the product documentation labels it as being version 8.0). So I guess it's just some weird numbering system?
  2. More importantly, has anyone told Portland General Electric what they're actually in for (read my first post on the acquisition if you don't know what I'm talking about)? I can't seem to find any instructions in the product documentation regarding how to upgrade from version 6.0 to version 8.0 (disclaimer: I haven't read the documentation cover to cover, so maybe it's buried in there somewhere). Are IBM actually going to help people upgrade gracefully or were they just paying customers lip service when they were assuring us that they would make it easy to do so? Here's Nishant's opportunity to suggest Portland General Electric switch to Oracle Enterprise Single Sign-On :-)

Update - Phill left the following as a comment:
"IBM has created a dedicated team of project managers and technical consultants to help customers in their migration of Passlogix to Encentuate - free of charge! This team has actually been assembled for sometime and out in the market place transitioning our clients."
It looks like IBM are doing something about it.

Tuesday, September 02, 2008

The union strikes back against IBM Australia

My better half sent me a link to this story today. It's about a bunch of IBM Australia employees at IBM's Flightdeck in Baulkham Hills having voted overwhelmingly to "strike for better pay and conditions". When they received no response from IBM, they tentatively agreed to strike this week on Thursday or Friday.

At first, it's surprising that IBM employees would strike given the industry and also the reputation of the company. You don't typically associate IBM with the unions. But the more I think about it, the less surprising it becomes.

Many of you know I used to work for IBM and hence I have some insight into what it's like, especially within IBM Australia. Some parts are better than others. I served time in support, consulting services and sales. By far the worst part of IBM to be in was operations. In IBM, operations roles are typically within managed service environments where an organisation has outsourced IT functions to IBM. Many of Australia's big banks have done this and the article did mention that Westpac (one of Australia's biggest retail banks) would be among the organisations affected.

The managed services/outsourcing area of the company just sucks the life out of most people, and being part of the business as a graduate straight out of university made me vow NEVER to work in support or operations ever again if I could help it (I know, never say never). Needless to say, I made a decided effort to run as far away from that role as I possibly could. To IBM's credit, they did manage to get me a different role because I whined enough and because they could (given that IBM are huge and have so many different types of jobs in different business areas) and hence kept me with the company.

I should point out that my time in consulting and in sales was much more enjoyable, so I'm not putting IBM down as a company. In consulting, you're still treated like a resource so at times you feel like a number but working conditions by and large are much better. My time with IBM Software Group sales was by far my most enjoyable within IBM. Absolutely no complaints about the conditions there. As a bonus, the people I worked with were first class and I remain in contact with many of them even today (don't forget I live in a whole other country now - but I always catch up with my ex-colleagues whenever I'm in Australia).

Conditions aside, one thing IBM has always lagged behind in has been salary. They DO NOT pay market rates. I'm not sure they ever will. As an example, a few years ago I turned down a concrete offer to join CA (with almost a 50% increase in salary - Update: I should probably point out that at the time, people with Identity Management skills were very much in demand and companies would pay a premium. I'm in no way suggesting IBM pays almost 50% below the market.) because my colleagues convinced me not to (one in particular whom I shall always refer to as "Baron"). To be fair, my manager also managed to bring my salary a little more in line with the market but it still wasn't close to CA's offer. Long story short, I stayed and really pissed CA management off for wasting their time (sorry guys and gals). My own example isn't the exception to the rule. I know of quite a few others who had similar stories and left to take higher paying jobs. That said, there are many IBM veterans who know very well that they aren't being paid market value but stay because of the fact that they like working for IBM. What I'm saying is that it seems IBM make a concerted effort not to pay market rates because of all the intangible benefits they provide (emotional or otherwise). This is fine if working conditions are up to par. But as I said, in some parts of the company it isn't (especially if you take into account how good some other parts of IBM are to work in).

Which brings me back to the employees working for IBM's Flightdeck in Baulkham Hills. They work in exactly the area I mention - operations and support. I hope IBM do something about giving them some of the things they want and avoid inflicting pain on their customers who pay them a lot of money for the service. It's long overdue.

Update (5 Sept 2008): The strike's been called off...for now.

Saturday, March 29, 2008

Passlogix responds to the IBM situation

There's been many a discussion around the IBM acquisition of Encentuate and what it means. I wrote about it here, here, here and here. I've also received a few emails discussing the issue (mostly with my IBM mates). I've presented the IBM view and an unofficial (albeit tongue in cheek) Oracle view (thanks to Nishant Kaushik). The obvious missing link here is Passlogix's view.

Earlier this week, I received an email from a senior member of Passlogix's management team to open up a discussion and also to clarify their position. One of the topics of conversation centred around one of my posts and specifically my statement:

If you "upgrade" from ITAM ESSO to Passlogix v-GO or Oracle's OEM version of v-GO, you will have to buy the product again. Your IBM licenses will not carry over, unless Passlogix and/or Oracle get very aggressive and agree to "upgrade" your deployment and waive the software costs

The next few paragraphs in orange summarise my understanding (not a direct quote, so it includes some of my commentary) of Passlogix's position.

Passlogix's response is that they are working with every customer running IBM Tivoli Access Manager for Enterprise Single Sign-On (ITAM ESSO) 6.0 (the current version and OEM of Passlogix v-GO) to give them options moving forward and to help give them a choice. They will also honour the existing maintenance contracts that IBM has in place, and if the customer chooses to have Passlogix support them directly, there will be no additional charges to do so.

Passlogix also completely agree with my point that upgrading from ITAM ESSO 6.0 (Passlogix v-GO OEM) to ITAM ESSO 7.0 ("blue rinsed" Encentuate) will be a real pain in the behind because it's a "rip and replace". They make mention of the fact that v-Go is an "infrastructure free/event driven technology" and Encentuate is "server based/script driven". I can't confirm that Encentuate is indeed server based and script driven because I have never seen it in action. If it is, then it will be very painful migrating between the 2 approaches. As an aside, I should point out that it's not surprising that they agree! It helps them keep existing customers. I'm sure every single Passlogix employee is being told to say this. Unfortunately for IBM, I'm right. So IBM, you're going to need to work VERY hard to make it worthwhile for a customer to move to ITAM ESSO 7.0.

One last thing that Passlogix would like to remind us is that if you're the type of organisation that MUST evaluate technology before you can implement it, you'll also have to put up with that pain (as will IBM) before you can migrate to ITAM ESSO 7.0.

IBM will obviously tell you that you do not need to evaluate anything and that it should be treated as an upgrade. How you choose to view it is completely your call. Just be aware that these are the 2 differing views and whichever you pick will have implications for your migration or upgrade plan.

At this point in time, here are your choices:
  1. Upgrade to ITAM ESSO 7.0 when it comes out - No additional software license, maintenance or support costs (unless your maintenance contract is expiring). Lots of services pain. Who pays for the services? If IBM doesn't wear most of it, they aren't trying hard enough.
  2. Move to Passlogix - No additional software license, maintenance or support costs (unless your maintenance contract is expiring). Services pain will probably be minimal if any. If you have other IBM Tivoli Security products deployed however, keep in mind that future integration points will probably be released for ITAM ESSO 7.0 ("blue rinsed" Encentuate) before Passlogix get a chance to write their integration pieces by virtue of the fact IBM will generally build their integration pieces between internal products first (not always, but this is almost always true within the same IBM product suite). I'm pretty sure Passlogix will continue to support integration between v-GO and the IBM Tivoli products, but they will just be slower in getting them released. There's not a lot Passlogix can do about it of course because they will only be able to build integration pieces into IBM products by working with IBM (unless they wait for APIs to be published, which will make it even slower).
  3. Move to Oracle - They'll charge you for the software, maintenance and support (does someone from Oracle want to email me to tell me that you won't?). Services pain will probably be minimal if any. If you have other IBM Tivoli Security products deployed however, this is not a smart choice unless you are ready to throw IBM out and replace your whole Identity and Access Management infrastructure with Oracle.

Thursday, March 20, 2008

Why did it take this long for someone to build a Web Access Management appliance?

Many IBM Tivoli (and ex-IBM Tivoli) people have been saying for years that IBM Tivoli Access Manager's WebSEAL component should be an appliance, not a piece of software you have to install. For those not familiar with IBM Tivoli's security products, WebSEAL is the web proxy that typically sits in the DMZ of your network and performs the authentication and authorisation for your Web applications. I won't go into a sales pitch about why that's a good thing. If you really want to know, ask your local IBM sales rep or send me an email via the contact form on this blog and I'll get back to you.

For one thing, an appliance will generally perform better. Extremely handy when it's the front door into your enterprise web environment. IBM will not disagree because they have an appliance product doing what WebSEAL does, but for Web Services. It's called WebSphere Datapower, which was technology IBM bought via the acquisition of Datapower in 2005. The specific appliance I'm referring to is the XS40, which I also had to know about for some time until IBM finally decided to stick it once and for all under the WebSphere brand. To be fair, it does have integration points into IBM Tivoli Federated Identity Manager so all you IBM security people shouldn't be ignoring it.

It's also become somewhat of a commodity. Every major vendor has one, calls it "Access Manager", delivers it on a CD (meaning it's software) and all have very similar core functions. They are just architecturally different. I suppose it wasn't worth the effort to make it an appliance even though it made sense. All these "Access Manager" products have been selling just fine as software components.

I've been catching up on my news items (when am I ever not) and stumbled upon these guys. They are P2 Security and have built exactly what I've just described. An appliance that does Web Access Management. They even have a comparison matrix against the big vendors, which by the way isn't exactly accurate. I already see some "crosses" against IBM that I know should be "ticks".

The one beef I have with this appliance from P2 Security is that they count having a policy server as being a negative (see the comparison matrix). I don't see why that is the case? They may argue that it presents management overhead. Sure, but I don't see any mention within their collateral of how they manage security policies when someone decides to buy more than 1 appliance.

If you are in the security game, you know it's a pain in the behind to have to change security policies (or any policies for that matter) in multiple places. Are they saying that if you have multiple appliances, each time you change the policies on one of them, you have to do it for the others? It may be tolerable if it's a simple policy change, but security policies are not usually simple when it comes to authorisation (aka entitlements, although in this case I don't think the appliance can get fine-grained enough to qualify as doing any real entitlement management). Any decent technology company will have an answer for my question, so perhaps they've already thought this through. I just can't find it on the site (maybe I'm not looking hard enough, but it's late so give me a break).

The main point to make here however, is that it remains a point solution. Useful if you are a small organisation that only wants to do Access Management for your web applications, but if you want a more coherent and integrated Identity and Access Management solution, you should probably go for one of the large suite vendors. That said, I applaud P2 Security for delivering what many have been asking for (but vendors have not bothered to build because the ROI on the effort didn't make sense).

Of course, they are a perfect target for acquisition by an Identity Vendor without an access management product. Did I hear someone say Courion?

Monday, March 17, 2008

Yes they're still talking to me

In my last post, I jokingly wondered if my mates at IBM were still talking to me. Thankfully, they are. *Phew*.

A few sent me messages pretending (at least that's what I assumed) to disown me as a friend/acquaintance, and then assured me that IBM understand what they've just done and as I expected, will be doing everything they can to minimise the pain for their existing IBM Tivoli Access Manager for Enterprise Single Sign-On (ITAM ESSO) customers.

Of course, that's exactly what you would expect IBM to do and say. As existing ITAM ESSO customers, you just have to make sure they follow through :-)

Saturday, March 15, 2008

I wonder if my ex-IBM colleagues will still speak to me

My thoughts regarding the IBM acquisition of Encentuate have been drawing quite a bit of traffic, so I guess it's a topic of interest this week.

Nishant Kaushik, Oracle's Architect for Identity Management Products gives his views on the whole thing including cheekily quoting me. I know it's all in good fun, so I'll respond in the same spirit...although I should ask if they've given him a new role as a member of the sales team? :-) Yes yes I know, the people in the product management/architecture team are evangelists by default, so they have a responsibility to help sell/evangelise their products.

He pinpoints my comments that the upgrade from IBM Tivoli Access Manager for Enterprise Single Sign-On (ITAM ESSO) 6.0 (the current version and OEM of Passlogix v-GO) to version 7.0 (the "blue-rinsed" version of Encentuate) is a "rip and replace". He suggests (tongue in cheek) that instead of going through the pain of upgrading to ITAM ESSO 7.0, customers should "upgrade" to Oracle's OEM version of Passlogix v-GO, the Oracle Enterprise Single Sign-On suite, because it'll be much easier moving forward and...
"could save many an enterprise many a headache."

While that's true in theory, customers could also go the direct route to Passlogix and just upgrade to the next version of v-GO. It's the same product with a different skin. I'm not saying I have a preference for Passlogix over Oracle. I'm just saying you have a choice.

Before you go rushing off and telling IBM where to shove their Encentuate product, the first question you need to ask yourself is, "do I have any other IBM Tivoli security products deployed?" In most cases, the answer will be "yes". If you do, the smart thing to do is to stay calm. Because if you have already invested in other IBM Tivoli security products, it's going to cost you a heck of a lot more to "upgrade" them to Oracle's versions. A "rip and replace" of your core Identity and/or Access Management infrastructure is going to be 1,000,000 times more painful than a "rip and replace" of your ESSO solution. If you only have ITAM ESSO, then maybe you can consider the "upgrade" to Oracle or Passlogix because you aren't as heavily invested in the IBM Tivoli technology. But I know IBM, and I know they will do their utmost to ensure they don't lose their valued customer base...especially over something like a strategic acquisition. I just hope IBM understands the position they have put their existing ITAM ESSO customers in by acquiring Encentuate and do everything possible to minimise the pain (IBM, please don't say "eliminate the pain" because that would just be lying, aka marketing).

Here's more food for thought, especially if ITAM ESSO is the only thing you have implemented from IBM Tivoli. If you "upgrade" from ITAM ESSO to Passlogix v-GO or Oracle's OEM version of v-GO, you will have to buy the product again. Your IBM licenses will not carry over, unless Passlogix and/or Oracle get very aggressive and agree to "upgrade" your deployment and waive the software costs (there's a thought for the sales management team in Oracle and Passlogix, assuming the latter feels like testing their already tenuous relationship with IBM)(UPDATE: Passlogix have responded to me via email in relation to their position. I have written a new blog entry addressing this). IBM will not charge you to upgrade to ITAM ESSO 7.0 if you already have 6.0 and your yearly support and maintenance haven't lapsed. That's just business as usual (assuming IBM haven't changed the policy since I left). The only cost you will likely have to incur as I said before, are the services costs (and any internal, intangible costs to business productivity because of the need to upgrade). If IBM want to keep customers happy, they'll need to somehow subsidise these additional costs. Charging customers the usual fees will not go down well. Remember, Oracle and Passlogix are just waiting in the wings and would like nothing better than to "upgrade" your customer.

So there's the choices as I see them. As a customer, you are actually sitting in a position of power at the moment. You just have to wear the pain of the potential "rip and replace" from ITAM ESSO 6.0 to whatever you choose as the "upgrade". IBM will be nice to you because they want you to upgrade to version 7.0. Oracle and Passlogix (I shouldn't count Sun, BMC, RSA or any other company Passlogix has "gotten under the sheets with" out of the equation here) will want to displace IBM from your environment. Just work out what's best for your organisation in the longer term after careful consideration.

As for my ex-IBM colleagues, the last I checked they were still talking to me, taking my calls and answering my emails. In fact, I know some of them subscribe to this blog (hi guys!). But if any of their existing customers read my previous post (or even this one), they may be getting some irate phone calls asking what IBM is going to do to help them upgrade painlessly and possibly getting yelled at for selling them a product that is essentially about to be "decommissioned" by IBM.

Sorry guys. I'm just telling it like it is ;-)

Friday, March 14, 2008

A bit more on the IBM acquisition of Encentuate

My previous post talked about the IBM acquisition of Encentuate. After writing it, I realised that I hadn't come across Encentuate's technology in the past apart from reading about them in news stories and being given awards. At least nothing I would call "quantifiable experience". So I did some digging and read some data sheets and whitepapers. I also had a look around the web to see what else was out there. Most of the things I found were people and news publications re-publishing the press release word for word or paraphrasing slightly with a couple of exceptions.

Information week has a nice article written by Charles Babcock that says a little bit more and makes a very good point. It points out that a large number of Encentuate's customers include organisations from the health care industry, an area where IBM Tivoli security has not had a good track record. I know this to be a fact. I rarely ever saw customers in the heath care industry during my IBM tenure and IBM Tivoli security worldwide has very few customer references in this area. Traditionally, IBM Tivoli's customers have been financial institutions and government organisations. Bringing Encentuate into the Tivoli family gives them a foot in the door to quite a number of heath care organisations that would otherwise have gone and bought an IBM competitive product.

John Fontana over at Network World also chimed in and mentioned that "IBM said Version 7.0 of its Tivoli Access Manager Enterprise Single Sign-On, which is expected to ship this fall, will be the first IBM-branded incarnation of Encentuate Single Sign-on." I alluded to this in my previous post, so it's nice to see IBM confirming it.

I also came across Gartner's good old Magic Quadrant for Enterprise Single Sign-On, 2007 which I believe is the most recent one (I didn't know they made their more recent reports freely available, but that's not the main point here). After looking at where both Passlogix and Encentuate were in the Magic Quadrant, I went straight to the section where Gartner addresses the strengths and weaknesses (they call this "Cautions") of each Vendor.

Here's what they say about Passlogix:
Strengths
  • Passlogix greatly leveraged its reseller relationships with IBM and Oracle this past year. It also made a deal with RSA to gain RSA Sign-On Manager customers. (Sign-On Manager was a modified OEM version of Passlogix v-GO.) Through this deal, Passlogix also obtained a tighter, more-streamlined integration of RSA SecurID to v-GO implementations.
  • Passlogix has a number of very large implementations, some with more than 100,000 users, and this year it added HSBC, one of the world's largest banking and financial services organizations.
  • v-GO's architecture is two-tiered, with credentials capable of being stored in a variety of back-end directories. Redundancy is predicated on the customer's directory implementation. Passlogix's sign-on automation is wizard- and parameter-based, so no scripts are used. Clients report that most applications can be integrated easily out of the box.
  • Stronger authentication support is good and is implemented using Passlogix's add-on Authentication Manager product.
  • Good, shared-workstation support comes with the add-on Session Manager product. Passlogix supports integration with various provisioning products using its add-on Provisioning Manager. It also provides an SSPR tool focused on the network password used for primary authentication for ESSO.
Cautions
  • Passlogix's internal support staff is relatively small, as compared with other larger vendors and given its growing customer base. Passlogix must leverage its resellers to provide support while still providing responsive code patch/fix support as problems are uncovered.
  • Reporting and auditing capabilities are provided through third-party tools.
  • Passlogix's standard pricing is one of the highest in this arena, when adding SSPR, stronger authentication support, and shared-workstation and provisioning support to the base-product purchase.
  • Some target systems can be difficult to integrate and will require additional time.

Here's what they say about Encentuate:
Strengths
  • Encentuate was founded in 2001 and is currently an ESSO pure-play vendor. Overall, Encentuate has a very good product set that customers like and a high rate of out-of-the-box integration with target systems.
  • Encentuate is the only vendor to provide access to all types of applications through a Web browser and without requiring the SSO client to be implemented on the workstation. The use of a virtual private network client is recommended for remote access from outside the network.
  • The Encentuate product set integrates with a good set of stronger authentication options and includes a unique product called iTag. This is a passive proximity/radio frequency ID reader with a tag that can be affixed to anything the user carries (often a physical ID or physical access control badge) and can be used as a form of authentication for the ESSO tool.
  • Encentuate's ESSO product set has excellent shared-workstation support and the ability to provide each user with a private desktop — not just the sharing of applications with a common desktop — as other vendors do.
  • Encentuate's price-for-value proposition is very good, providing shared-workstation support, SSPR and stronger authentication integration for a lower price than most competitors.
Cautions
  • Encentuate's main challenge is to gain market share more aggressively. Management changes in 2006 left Encentuate to trail similarly staffed competitors in sales growth.
  • Encentuate must establish broader sales and integration partner channels to gain market share.

The first thing I noticed was that I had forgotten about Passlogix's OEM relationship with RSA. This, in addition to the agreements with Citrix, IBM and Oracle further solidify the view that it's part of Passlogix's strategy to find as many channels as possible without worrying about the other partners they might annoy along the way, no matter how large they may be (Citrix, RSA, IBM and Oracle are certainly not lightweights).

The second thing was that Gartner seems to think Encentuate is a good product, their drawbacks being the number (or lack) of deployed customer references (which Passlogix has a lot of) and sales challenges. Assuming you believe Gartner (and sometimes people can be a little skeptical of the analysts, even Gartner), then I dare say the acquisition by IBM solves the "cautions" presented by Gartner about Encentuate. Gartner will now have to find other "cautions", but it looks like they will have to put IBM in the leaders quadrant for Enterprise Single Sign-On pretty soon.

UPDATE: I just found what Gartner has to say about the acquisition. They released it 2 days after I wrote about it, but for those that like to know what Gartner thinks you can read it here.

Thursday, March 13, 2008

IBM acquires Encentuate - did they just dump Passlogix?

My former employer (IBM) is at it again. They've made another acquisition to add to their IBM Tivoli Security suite. This time they've acquired Encentuate, which provides an Enterprise Single Sign On (ESSO) solution in conjunction with strong (and multi-factor) authentication capabilities. They also added to the whole story by announcing the "forming of the IBM Security Software Laboratory in Singapore", which to the innocent bystander sounds like IBM are investing in Singapore and also expanding its "research" operations. In reality, it's "IBM speak" for "we just bought a company that had a bunch of developers based in Singapore and we are turning those offices into another 'lab' that we can add to our list of software labs around the world". The whole lab thing is not the point here. I just thought I'd decode that part of the press release for the non-IBM alumni out there.

So who are the ones most affected by this acquisition?
  1. Any customer who has bought and implemented IBM Tivoli Access Manager for Enterprise Single Sign-On (ITAM ESSO).
  2. Passlogix.
For those that are unaware, ITAM ESSO is an OEM of Passlogix's v-GO product suite. IBM did not hide this fact when they first announced the release of ITAM ESSO. The integration points into the relevant parts of the Tivoli Security product suite were built-in nicely once v-GO had been "blue rinsed". It made sense in early 2006 when the announcement was made. In fact, a lot of us internally at IBM Tivoli fully expected Passlogix to be acquired by IBM eventually once the OEM agreement had been fully "road tested" and proven to be a money maker for IBM. I'm sure many Passlogix employees thought the same (I know of one IBM Tivoli employee who left for Passlogix and used the "I would not have made the decision to leave if the company I was going to did not have a real chance of being acquired by IBM" reason in his farewell email).

Halfway through 2006 (not long after the agreement with IBM), Passlogix announced the same thing with Oracle, one of IBM's major competitors in the Enterprise Identity and Access Management space. You don't need to be a genius to work out that IBM Tivoli's management team were not amused.

Passlogix actually also have an OEM agreement with Citrix for use in their solution, although I should point out that this preceded the IBM agreement and only uses sub-components of the v-GO product suite (so I've been told by some of the Passlogix guys). Consequently, the real thorn in IBM's side was the agreement with Oracle.

In other words, Passlogix shot themselves in the foot by hedging their bets with both IBM and Oracle. Sooner or later, one of these 2 giants of the software industry was going to toss Passlogix out the door like a rag doll...although still with a thin thread attached. I don't know why Passlogix didn't see it coming. Let me explain the thin thread analogy.

IBM now finds themselves with an ITAM ESSO product that is essentially a competitor to Encentuate, which they have just bought. They have also sold ITAM ESSO to many customers in the world (if I was involved in selling you this thing, I apologise profusely - I had no idea). Being IBM and with a reputation to uphold, they will still have to support it for customers that have bought it. In parallel, they are going to have to "blue rinse" Encentuate and out of the colouring process will emerge ITAM ESSO! In other words, the next version of ITAM ESSO will be the "blue rinsed" version of Encentuate. What will marketing do with this? Here's my guess:
  1. Announce (probably informally - essentially just "socialising" the news to existing customers through the sales teams) an impending upgrade to ITAM ESSO 6.0 (Passlogix v-GO).
  2. "Blue rinse" Encentuate.
  3. Announce the release of ITAM ESSO 7.0 with new, major functionality including strong and multi-factor authentication, remote single sign on and additional logging and auditing which is integrated with IBM Tivoli Compliance Insight Manager (actually, this last bit will probably be released in version 7.1 because IBM product management will just want to get core 7.0 out the door ASAP).
Seamless? Almost. What marketing won't say is that the "upgrade" from 6.0 to 7.0 is essentialy a rip and replace. There is no seamless upgrade. Sure, they'll probably offer some tools to "help", but the upgrade process will need professional services either from IBM Software Services or IBM Business Consulting Services because the single sign on templates will be completely different between the Passlogix and Encentuate products.

Apart from existing ITAM ESSO customers, Passlogix is the other obvious loser. IBM will need to keep its relationship with Passlogix because they still need to support version 6.0 and Passlogix are ultimately the "development team" in this instance. This arrangement will only last as long as customers are on version 6.0 or when IBM decide to stop supporting version 6.0. From memory, upon release of a new version, IBM will officially support the n-1 version for 2 years starting from the date of release of the new version. I don't know if the policy has changed, but if it hasn't this means that the IBM and Passlogix relationship will only last for a further 2 years starting from the release date of ITAM ESSO 7.0.

I can only imagine that Passlogix is suddenly being extra nice to Oracle because it looks like they have just lost IBM as a potential suitor to sell to. It also means they cannot rely on pushing the acquisition price up by hoping that IBM and Oracle start a bidding war. At this point in time, Passlogix have 1 suitor. Oracle. IBM has found something "better" and as a bonus, they just added strong authentication to their kit bag!

UPDATE 1: I just read the Burton Group's reaction to the acquisition and it reminded me that Sun also has a partnership with Passlogix. It's not an OEM one to the best of my knowledge, but Sun could perhaps be a suitor for Passlogix. I still think Oracle's the more likely option however, as Sun has hedged their bets as well because of their partnership with ActivIdentity (one of Passlogix's major competitors).

UPDATE 2: Chris (I don't know his full name because he doesn't publish it) just left me a comment in response to this post to point out that BMC are also a Passlogix v-GO reseller. I actually went back to take a look at Passlogix's list of non-OEM partners and true enough, BMC is on there. If you look down the list, you might also notice that Novell is listed. I don't know if it's a reseller agreement or just a technology integration certification/partnership, but Passlogix are sure hedging their bets even more than I initially thought. I still believe that Oracle are the number 1 suitor and the vendor most likely to acquire Passlogix, but at least having all these partnerships gives Passlogix options if things don't go well with Oracle.