Monday, September 10, 2012
The Stages of Identity
Thursday, February 03, 2011
Learning from your mistakes
I love making mistakes. It's probably the best teacher in this world of Identity Management. In honor of that (and before the technical content, some thoughts on making mistakes:
Never say, "oops." Always say, "Ah, interesting." ~Author Unknown
It's always helpful to learn from your mistakes because then your mistakes seem worthwhile. ~Garry Marshall, 'Wake Me When It's Funny'Lost some time on my current project while NetWeaver needed to be reinstalled, no big deal since I could prototype a few things on my local environment and try and prepare for some of the challenges we knew would be coming up. Nevertheless, as soon as the server was ready, I was eager to get going.
Reconfiguring NetWeaver went through without a snag. We even were able to observe a few things that were done differently the rebuild and documented some best practices. When things are going this well, I should know better and start concentrating on what I'm missing. There's just too many things going on for things to be going this smoothly.
We configured the JDBC Driver and then the JDBC Datasource (IDM_DataSource) which went through without a problem (and part what caused us grief before) My "Spidey Sense" should have been going off like crazy now.
We then went in and configured the Roles and a test user. Then we setup that same user in the Identity Store via the MMC console. Now it was time for the big test, loading the Web UI, which came up with no errors (We were also getting Access denied, service down messages from the Web UI last time around). We logged in, which was further than we got before, but we still had a problem.
We only saw the Monitoring tab. I checked the assigned roles for the user and removed idm.monitoring.admin (my read/write role for monitoring), logged back in and still only saw monitoring. How strange.
Did some thinking, did some Googling, read some slightly related SDN posts with no clear relation or answers and did some more thinking.
As I pondered the install process and the login process, it hit me! Turns out we were so excited that we skipped an essential step! We never configured the JMX layer and set the Identity Store value or the Keys.ini location. (Good thing I only tried to log in and not change any passwords!)
Loaded NetWeaver Visual Administrator, navigated to the Configuration Adapter node and found the tc~idm~jmx~app node and flipped on edit mode, made the two changes and I don't even think I needed to log in again, all my tasks came up on a Web refresh.
I made a dumb mistake and got ahead of myself. Fortunately we got it all working without too much time lost.
So what did I get from this:
- Always follow the documentation. It's the best way to make sure you don't forget anything.
- If you're having a problem, use tools like Google and SDN. Even a "slightly related" posting can help you brainstorm.
- Get another set of eyes to look things over. People from the BASIS team can be your best friends here. Even if they've never heard of IDM, they probably know more NetWeaver than you.
- When all else fails, go back to #1 and RTFM, most likely you misread something!
Do not fear mistakes. You will know failure. Continue to reach out. ~Benjamin Franklin
I've learned that mistakes can often be as good a teacher as success. ~Jack Welch
Tuesday, February 01, 2011
Another Blogger comes up to Bat
Ian seems to be the first of a new breed of IdM consultants making the change from traditional SAP consulting to Identity Management. From reading the first few posts, it seems clear that he has both theoretical and field experience, which is always a welcome combination. I'm looking forward to seeing what he has to say in the coming months, and I think you will too.
Look for posts on his blog and on SAP SDN.
Welcome to the team, Ian!
Thursday, January 13, 2011
Some quick reads in SAP IDM and IdM in general.
It's also nice to know our market is growing!
Tuesday, November 09, 2010
Dispatcher Tips
However one of the things that sometimes gets forgotten in a NetWeaver Identity Management solution is the use and configuration of dispatchers. These seemingly small pieces of the configuration are responsible for a great deal of the operation of NW IDM, as they actually process and execute the provisioning jobs in the workflow.
There are a couple of basic rules of thumb that should be considered when planning for deploying dispatchers in a productive environment.
- There should only be one dispatcher per host. If anyone has any data on this, I’d love to see it. In an ideal world, it would be one dispatcher per physical host. I have not done any testing in virtualized environments, but I don’t see that as being a huge issue.
- Plan on one dispatcher per about every 25,000 users.
- If you have specific types of tasks and workflows that require special access, create a specialized dispatcher that supports them. Specific examples would include password management and deprovisioning.
Friday, May 21, 2010
Conflicting Views on IdM Acceptance
- While both articles mentioned that the Cloud could be a great IdM enabler, there was not much mentioned in the way of Architecture models by which this could be addressed. Guess you have to engage Forrester for that information.
- Looking for IT and IS goals such as Privileged User Management can be a great way to gain additional acceptance for an IdM project.
- Another issue that the articles do not mention is that acceptance can be promoted by leveraging established ERP application. Both Oracle and SAP now have Identity Management Systems that have specific functionality to provision in their respective internal landscapes as well as to the Enterprise in general. IBM also features similar tools for their infrastructure. Seems to me that along with Privileged User Management as discussed above, this could be another tool to gain IdM project acceptance (and more importantly, budget dollars) Quite a few project proposals I've come across lately are adopting this methodology.
- Understanding the Identity related needs of the organization
- Prioritizing those needs based on potential return which could be based on, time savings, monetary return (ROI through reduced Help Desk calls) or consolidation of workflow, portals and other IT infrastructure, and ability / time needed to design and develop the parts of the solution
- Executing a Project Plan based on these criteria
Tuesday, March 09, 2010
Managed Services Models for IdM: Slomin Shield or Roto-rooter?
- Slomin’s is an Alarm Company that offers central service monitoring. If they detect a problem, they call, assess the situation and take appropriate action.
- Roto-rooter is a plumbing company known for their quick response to service calls.
- The Roto-rooter model is a reactive model. When an organization sees that something needs to be done, a call is made for support services. More often than not, there is an arrangement for providing these support services. Engagement is made on an as needed basis for dealing with enhancement and upgrade processes.
- I would characterize the Slomin’s model as a more proactive model. In this model, there would be ongoing monitoring to make sure essential servers are responsive. As soon as incidents are uncovered contact is made with corporate IT to provide information on system status and likely causes of the problem. Resolved incident details would be entered into a knowledge base to provide historical data not only on what failed, but why it failed. Furthermore there is an ongoing review of needed enhancements and comprehensive review of patchers to determine applicability.
Monday, June 22, 2009
Promising News
The basic fact is that businesses save money when they implement Security and Identity Management projects. The costs of one security breach, password exploit, compliance violation, etc. dwarfs the investment and maintenance of a sound enterprise security infrastructure.
I found it interesting that the experts quoted in the article specifically referenced, encryption, compliance and Identity and Access Management technologies. I would also recommend the use of SSO technologies which make it easier to enforce password policy and promote compliance.
In the war of data security, a good defense is the best offense.
Monday, June 15, 2009
The Yo-yo theory
Everyone knows IT spending is important and can result in real benefit to the company however, there's a tendency to use yo-yo budgeting.Maybe the reasoning is a bit simplistic (after all I'm an IdM architect, not an economist) but I think it holds up and I'm pretty sure that this model would extend beyond IT as well. I'm wondering how much the model holds, does a slower decline mean you can stay down longer or not? Does each department have it's own yo-yo?
When things get tough, the yo-yo is dropped as spending slows and we expect IT to run on the bottom for as long as possible, but eventually we need to catch up and snap the yo-yo back up and we catch up on technology.
Where's an economist when you need one?
Thursday, May 07, 2009
New School Identity Management?
All due respect to Mark, who I know has been around the IdM world for some time, but none of these elements should be considered New School and have been around for quite some time.
- Privileged Account Management - I don't know of an engagement I've worked on in the last 5 years that did not have some concern about the creation and management of both Privileged and Service accounts. If anything, because of their nature, these accounts have a greater need to be created in such a way that they are done according to mandated processes and recorded for audit and review.
- AD Bridges - While not a technology I've gotten to work with a lot I know that many a mixed UNIX/Microsoft shop consider the Vintella/Quest tools to be indispensable.
- Virtual Directories - Again, a technology that's been around for a long time. I've been working with Virtual Directory technologies since 2004, where I would commonly show customers how to map information, provide access controls and even used the Virtual Directory as a write back mechanism to supported repositories.
However, in the end, the design and implementation of an Identity Management solution must be holistic in nature. Regardless of one's opinion on the New School qualities of the all the technologies Mark mentions in his article, they must all be considered and planned for in the final design.
Tuesday, April 21, 2009
Where oh Where will MySQL go?
- Sun offers both hardware/OS layers, Java, and is the Elder statesman of the IAM space
- Oracle offers the database and is showing great momentum in the IdM and ERP spaces
- SAP offers an ERP suite with tight integration via NetWeaver
Wednesday, April 01, 2009
Other thoughts on Implementation
The only thing I might add to this is that a good pilot can be a lead in to Phase I. Additionally, good background work in the form of Business Analysis and Architecture design goes a long way as well.
Tuesday, March 31, 2009
New White Paper!
The hand is healing nicely and the Paper has just been published. Please let me know what you think.
On a related note, I also had a brief article posted on SAP Developer Network SAP Weblogs: Identity Management.
Monday, February 23, 2009
Managing Project Communication
I've written before on the topic of how to prevent project failures, but very little about what happens as projects are failing. I was recently chatting with some colleagues about what does happen when a project begins to head south.
First of all, there always seems to be a tendency to blame the outsider. Basically this argument looks something like: "You never got the requirements right (from the customer) / you never delivered correct requirements (from the consultant)"
What does this boils down to is a failure in communication. Now the question from a risk management approach is how one keeps this communication in sync. Based on our discussion we came up with the following:
- Regular status meetings. If your executive sponsor is not at these meetings, schedule regular steering committee updates which should be just the project manager(s), architect(s) and the executive sponsor. They might not need to be weekly, but they must not be optional any of these people. Do not rely on only one side to make these reports. Everyone must be on the same page. Make sure the sponsor is aware of the key challenges so that there are no surprises.
- Obtain consensus and settle the issues quickly and decisively. If there are dissenting opinions about major decisions, get the issue settled once. Don't keep circling on the issue. If there's an issue that just won't go away, get the parties in front of the executive sponsor as I've noted above. Get a final ruling and move on.
- Establish change controls. For some reason, no one likes to use these. There's a feeling that these are things to hide behind, rationalize additional cost or bog down the project in extra paperwork. None of these are true. All that's being done here is making sure that all project principals are aware of the change. This establishes responsibility and sets up controls for making sure that things don't get out of control. And I'd imagine that the amount of paperwork involved in a change control is minor compared to having to write the report of why the project failed. Trust me, this is not fun.
- Use and establish some sort of project strategy/methodology. I don't care what it is, but make sure a project plan exists and that there is structure in place. There should be a project manager who will make sure that there is a plan to complete the project, but the architect and senior engineers should make sure that there are development standards which must also include documentation!
These points are intended to increase communication and decrease mistrust and politics. If the project team meets regularly, tracks what they are doing and how the project changes and has a structure for managing progress and change there is less of a chance of having a post-mortem and more of a chance of documenting the best practices that were done right!
Monday, January 19, 2009
SELECTing from the Identity Store
The basic use case is this: The Identity Management solution needs to do a look up between an incoming data feed and the Identity store. The basic idea is that if the value from the feed and the value from the Identity Store match then the entries match and updating/provisioning can proceed as directed by workflow. I'm sure you can imagine other use cases, looking up managers, phone numbers, and other frequently used attributes.
The feed processing job will use a script to evaluate the match. Most likely it will pass MSKEYVALUE but could also use some other unique attribute in the feed.
The first thing that is needed is to determine the MSKEY, if any, for the entry to be worked with. To this end, I created the following query which will be implemented by NW IDM's uSelect function, which can be used in a Provisioning Job or Reconciliation task. Following best practices for NetWeaver Identity Manager, I am using the JAVA engine and therefore JavaScript in this example.
//Create an uppercase version of Par for checking against the SEARCHVALUE
uPar = Par.toUpperCase();
MSKEYQuery = "select mskey from mxiv_sentries where (searchvalue = '" + uPar + "')";
MSKEYResult = UserFunc.uSelect(MSKEYQuery);
You'll notice one of the first things we need to do is make sure we access the searchvalue correctly. Elements in this column always have their text elements stored in Uppercase, so we need to make sure that for the purposes of searching, we have an uppercase value handy. The results of this query are stored in a variable called MSKEYResult. Now that this information is available, we can now search for needed values related to this entry.
EmployeeNumQuery = "select avalue from mxiv_sentries where (mskey=" + MSKEYResult + ") and (AttrName='HR_EMPNUM)";
EmployeeNumResult = UserFunc.uSelect(EmployeeNumQuery );
With this query I can now look for a specific attribute value for a specific user and store it in a variable. At this point we should plan on returning a more nicely formatted version of the attribute so we will return aValue rather than SearchValue which is the value for the attribute as it entered into and subsequently processed by NW IDM for use in screen output, reports, emails, etc. In this example we are returning the user's Employee number.
This process might also include another query to do a count of returned Employee Numbers to protect against potential "dirty data" entries (multiple identities for the user or to many users with the same name.) If this scenario occurs more detailed searching, involving more attributes might be needed.
Note: I don't necessarily claim that this is the best or most efficient methodology for accessing this information. All I know is that it works for me and the way that I think / process information. If anyone has ideas on making this better or properly using the embedded functions listed above, I'd love to hear about it.
Friday, December 12, 2008
Why do We Bother With Server Virtualization, Anyway?
Friday, May 23, 2008
Non technical updates
Thursday, May 01, 2008
Most important things to ensure a successful project
I believe there's a core item that both the client and the implementer can bring to the table to help ensure success.
From the Implementer, it is essential that a good business analysis effort takes place. I don't think that anyone expects that this can happen in one or even a few sessions. However, the person(s) who are doing the current/target state analysis, must ask probing questions and follow up on them. It's important that the BA has a complete and thorough understanding of what the customer has and what they want. This can be a delicate process as the BA and customer learn about each other and the processes. One of the BA's best tools in this effort is to make sure they have a good process to work with. Templates, flow charts and other tools can create efficiencies in this process.
From the client side, preparation is the key. Having documentation on current processes and flows is most helpful to make sure that the project team succeeds in delivering the correct and complete product. Now we all know that not all of this information will be available when needed, but having the SMEs on call and tracking gap items helps to remediate this. Strong client side PMs and executive sponsors are also critical in keeping this an efficient process.
Ultimately it is the synergy that is created by the client and implementation teams that brings out the best results. With both sides working together the greatest progress is made and the best results are to be had.