Developing a single sign-on (SSO) approach for identity management that actually works across multiple Web sites remains one of the thorniest Web application development issues in all of IT.
In an Open SSO Express for Improved SSO webinar presented by Sun Microsystems, the virtues of an open-source application that manages SSO are presented.
According to Daniel Raskin, chief identity strategist for Sun, one of the goals of Sun’s Lazy Programmer’s Manifesto is to make sure that developers never have to write identity management code again. To that end, Sun is shepherding through the open-source community an SSO Express application that eliminates the need for one-time passwords and tokens for the purpose of identity management.
There is not a lot of detail on exactly how SSO Express works, but there are a lot of demonstrations of the technology in action. In addition, Sun shows a light-weight implementation for Microsoft.Net sites, shows how the technology can reach out to include existing Web applications such as Salesforce.com, and promises support for Cisco’s WebEx platform in a future release.
There’s also a discussion of how an OAuth approach to identity management can eliminate the need for more cumbersome WS-Security implementations.
Rating: 



Solid discussion of a fairly thorny problem – TWM1.



