• Home
  • Blog
  • About
  • Contact
CloudAve
Software in Business. The Business of Software.
  • Business
    • Analysis
    • Entrepreneurship
    • Marketing
    • Strategy
    • Small business
  • Technology
    • Application Software
    • Infrastructure
    • Open Source
    • Mobile
    • Platforms
    • Product reviews
    • Security
  • Misc
    • Design
    • Just for fun
    • Trends & Concepts
  • Sponsors
Browse: Home / AuthN, AuthZ and Gluecon

AuthN, AuthZ and Gluecon

By Eric Norlin on April 26, 2010

As I’ve mentioned many times in the past, I’m not an engineer. Still, along the way, even the non-engineers like me pick up some tidbits of knowledge. One of the things I learned in my years spent in identity management (”IdM”) is the difference between Authentication (”AuthN”) and Authorization (”AuthZ”). And, as it turns out, that learning is useful.

Take the confusion over OAuth and OpenID. OAuth is “Open Authorization,” while OpenID is an authentication mechanism. While AuthZ and AuthN sometimes feel very similar, they’re actually a pretty different operation.

Authentication is about verifying a person as they login to an application. Authentication can be 1 factor, 2 factor, 9 factor, whatever. It could require DNA if it feels like it. OpenID is about maintaining the “authenticated state” across different sites — what all of us call single sign on (SSO).

Authorization is about granting the ability to access resources or use an application without requiring that the authenticated state be passed across the websites. You LOG IN to twtiter. But you don’t have to log in to a twitter app that wants to gain authorization to your twitter data. You, the authenticated person, *authorize* the application to have access to those resources. The app doesn’t need you to authenticate. And the state of your authentication doesn’t need to persist across the two sites. Hence, the oft-used analogy of the “valet key” being compared to OAuth — it “authorizes” the valet to use certain resources in the car (drive it in a given radius, etc), but it does not “authenticate” the valet to be “logged in” to the car.

As this article points out, OAuth is becoming THE big deal in identity management (in the consumer space). And rightfully so. Authentication is important, but *authorization* can be leveraged. Authorization is built for network effects.

Not that authentication isn’t necessary. It is. It’s just not as sexy.

Fortunately, you can get both sides of the equation at Gluecon, as we’ll be covering OAuth (including the new Web Access Resource Protocol work), and the whole SAML/OpenID complex. If you’re building cloud or web apps, you simply have to understand the implications of all sides of this one. And you can get that at Glue.

We’re 30 days from the conference, so don’t delay — use “twit2″ to take 10% off of your registration, and register today.

(Cross-posted at Glue )

Posted in General | Tagged authn, authz, conferences, gluecon, oauth, openid

Eric Norlin

« Previous Next »
feed mail facebook twitter linkedin
  • Tags
  • Calendar
  • Comments

accy2 amazon android Apple aws briefs cloud cloud computing collaboration conferences defragcon Enterprise enterprise 2.0 Entrepreneurship facebook google humor iaas IBM innovation insights integration ipad iphone marketing microsoft netsuite open source paas saas salesforce.com sap Security smb Social Business Social CRM social media Start-up Advice Startup Advice startups Tech Market Analysis twitter vc funding venture capital xero

February 2012
M T W T F S S
« Jan    
 12345
6789101112
13141516171819
20212223242526
272829  
  • Krishnan Subramanian: Well, I am open to...
  • Mathew Lodge: Thanks for the clarification. You...
  • Krishnan Subramanian: Mathew, Thanks for your...
  • Mathew Lodge: Krish, I run the vCloud team at...
  • Krishnan Subramanian: It doesn’t have any...
  • Clark Updike: Can you elaborate on the tie-in...
  • Owen: Guess I’m more cynical than that....
  • Krishnan Subramanian: Thatz exactly what I told...
  • Aswath Rao: Scoble is misframing his arguments...
  • Krishnan Subramanian: I never said DevOps goes...
  • Adron: I’m late on this article…...
  • Chirag Mehta: I agree that iMessage exists, but...
  • Can OpenSocial Be Resurrected In The Enterprise?: ...
  • Can OpenSocial Be Resurrected In The Enterprise?: ...
  • cloud30 – SME comprehensive cloud computing solution: ...

Sponsored Content

Introducing Zoho Support Express Plans complemented with a brand New UI
Introducing Zoho Support Express Plans complemented with a brand New UI
Digital Nibbles: The Consumer Cloud & HighTechDad - That’s a Wrap!
Digital Nibbles: The Consumer Cloud & HighTechDad - That’s a Wrap!
Dispatch Jobs made easy with vWorkApp and Zoho CRM
Dispatch Jobs made easy with vWorkApp and Zoho CRM
HR Technology Prediction for 2012: Year of the Tablet
HR Technology Prediction for 2012: Year of the Tablet
Cloud Computing Beyond the Enterprise: Livecasting the Consumer Cloud
Cloud Computing Beyond the Enterprise: Livecasting the Consumer Cloud
Why Finance Gets Strategic HR
Why Finance Gets Strategic HR

Archives

Authors

  • Adron Hall
  • Ben Kepes
  • Chirag Mehta
  • Chris Yeh
  • Christian Reilly
  • Dan Morrill
  • Dave Michels
  • David Terrar
  • Hutch Carpenter
  • Jacob Morgan
  • Jarret Pazahanick
  • Joel York
  • John Taschek
  • Krishnan Subramanian
  • Maksim Ovsyannikov
  • Mark Fidelman
  • Mark Suster
  • Martijn Linssen
  • Paul Miller
  • Raju Vegesna
  • Randy Bias
  • Sadagopan
  • Zoli Erdos

  Sponsored by Intel,  Workday and Zoho