advising on IT-business alignment
IT-business alignment about us blog our services articles & reports resources your profile exposure
blog
blog
Tuesday, March 06, 2007

BEA announces strategic partnerhsip with CA: but where does that leave AquaLogic Enterprise Security?

BEA today announced a stategic partnership with CA, which will see the latter's access and identity management solutions (SiteMinder and Identity Manager) integrated with the former's WebLogic and AquaLogic application and service infrastructure platforms.

I agree completely with Wai Wong's (BEA's executive vice president of products) statement in the press release that

Identity and Access Management is critical within SOA

not least because we have said as much in our service infrastructure assessment model and our report on identity management.

Despite this agreement, I am still left a tad confused by this partnership as it is far from clear what this means for AquaLogic Enterprise Security (ALES), which BEA describes as

a fine-grained entitlement management solution that combines centralized policy management with distributed policy decision-making and enforcement. This combination provides management and control of your critical applications

How will SiteMinder integrate with ALES? Will ALES continue to integrate with other identity and access management solutions? Does BEA plan to provide a common policy definition and enforcement framework across ALES and SiteMinder?

We point out in our assessment of BEA's service infrastructure offerings that there are some important gaps when it comes to security and identity management, which explains why BEA felt the need to establish this partnership. However, as well as answering a number of questions from potential adopters, this partnership is going to raise a few more for existing customers with an investment in ALES. I for one look forward to learning more about the two companies' plans to

validate and further extend integration between CA SiteMinder and BEA WebLogic and AquaLogic technologies

Labels: , , ,

Comments:
SiteMinder provides the authentication & web SSO, while ALES provides fine-grained authorization, data redaction, attribute-based entitlements for your portal, data & proxy services, Java EE, etc. CA passes its identity (typically maintained in a cookie) to ALES via identity assertion SPI.
 
This certainly clarifies things from a functional perspective Matthew. I wonder whether the integration provides a common approach to management, auditing/logging, policy definition and so forth?
 
I envision identity (user/group) being managed through CA IdentityMinder and/or their provisioning product if either is in the picture, with entitlements (roles, permissions, authorization) and policies being defined & managed through ALES Entitlements administration.

I think there will be one or more 3rd parties that comes into the picture for governance, auditing, compliance, etc. via OEM or acquisition.
 
Post a Comment

<< Home


Burn this feed
Burn this feed!

Creative Commons License
This work is licensed under a Creative Commons License.

Blog home

Previous posts

Our first identity management assessment
Five things you don't know about Neil WD
Has Microsoft got BPM?
First MWD FM SOA interview: David Clarke, Cape Clear
MWD FM kicks off interviews with SOA vendors
TIBCO's ActiveMatrix and 4GL for SOA
Internet-scale identity systems
EMC strikes while the virtualisation iron is hot
Bill Gates says goodbye to the RSA conference - an...
A couple of interesting CardSpace snippets

Blog archive

March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
May 2008
June 2008
July 2008
August 2008
September 2008
October 2008
November 2008
December 2008
January 2009
February 2009
March 2009
April 2009
May 2009
June 2009
July 2009

Blogroll

Andrew McAfee
Andy Updegrove
Bob Sutor
Dare Obasanjo
Dave Orchard
Digital Identity
Don Box
Fred Chong's WebBlog
Inside Architecture
Irving Wladawsky-Berger
James Governor
Jon Udell
Kim Cameron
Nicholas Carr
Planet Identity
Radovan Janecek
Sandy Kemsley
Service Architecture - SOA
Todd Biske: Outside the Box

Powered by Blogger

Weblog Commenting and Trackback by HaloScan.com

Enter your email address to subscribe to updates:

Delivered by FeedBurner