Showing posts with label RSA LifeCycle & Governance. Show all posts
Showing posts with label RSA LifeCycle & Governance. Show all posts

Tuesday, February 28, 2017

Gartner Magic Quadrant - IGA 2017

I woke this morning and received an email from SailPoint. It maintains as the leader in Identity Governance & Administration (IGA) market as named by Gartner for Q1, 2017.




Not a surprise for me to see SailPoint up there in the chart. 

What really surprised me is how RSA has been dropped from Challengers quadrant to Niche Players quadrant after being merged with Dell Technologies. As far as I know, there is no change to the product line. 

Another surprise is CA Technologies has managed to move from Visionaries quadrant to Leaders quadrant. This is largely due to 2 changes, from our own experience.


1) CA Identity Portal

This is a product developed by a company SIGMA recently bought over by CA. With this Identity Portal in place, the user experience has improved drastically.



The old UI looks similar to the one shown below. Sucks big time!



2) CA Identity Suite Virtual Appliance

The Virtual Appliance is a full-featured deployment of CA Identity Suite, pre-installed and pre-configured in a virtual machine image format. Installation is no longer needed.

If you have experience installing Oracle and CA products, you will know what I meant by "pain-in-the-xxx" during installation. Due to the complexity in the various components within the same product, installation takes forever and this eats into the professional service man-days. And overall, your total pricing will not be attractive!

The Virtual Appliance supports a variety of deployment options and is available from CA Identity Suite 12.6.8 CR1 onwards.


Note: I have not read the report in detail yet and have no idea how the evaluation was made. Above is my own personal experience using the 2 products. 

.



Wednesday, June 29, 2016

Connectors for Identity Provisioning

We have an intern working for us before he reports for National Service next month. So we gave him some exploration tasks, one of it being to automate our onboarding process using OpenIDM.


New staff on boarding procedures for our office:
1. Create an AD Account
2. Create Zimbra Email Account
3. Create VPN Account
4. Create SVN Account
5. Create Helpscout Account
6. Create Slack Account
7. Create JIRA User
8. Add user to Google calendar

Simple task. Should be able to finish within a month.

No.

Tasks like creating a Zimbra email account, VPN account and SVN account are command-lines operations, thus we need a SSH connector. Took a quick look at https://forgerock.org/openicf/docs/connectors/. Happy! We thought we can workaround with the Solaris Connector.

But no again... the link was broken.

Raised a ticket with Support and was told a new SSH Connector is going to be released soon for OpenIDM 4.0.

Before that happens, what can we do? Generate a flat file using CSV Connector; Run a script to execute the commands on target systems. Less than ideal.

So sometimes, things like this do happen. When you look back the design after implementation, you would like : "OMG! What the hell? Who did that?" Mostly not asking what was the limitation when a design decision was made.

Side track a bit... So we were looking deep into RSA Via Lifecycle & Governance. One thing we like about their architecture was a Mulesoft engine was embedded, which provides the connectivity to external systems. Mulesoft has tons of connectors out there (https://www.mulesoft.com/exchange#!/?types=connector). Ok, not all are Mulesoft-certified, but I would think if one is certified, it would also mean the cost will be different. :)




So, one of my Identity Specialist went crazy and wanted to integrate OpenIDM with Mulesoft. It has what we want - SSH, Slack, JIRA.

Will try. :)

.