<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Steve Tout&#039;s Blog &#187; Oracle Identity Management</title>
	<atom:link href="http://www.stevetout.com/category/oracle-idm/feed" rel="self" type="application/rss+xml" />
	<link>http://www.stevetout.com</link>
	<description>Identity Management in an Uncertain World and Other Random Things</description>
	<lastBuildDate>Tue, 31 Jan 2012 17:47:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Is the Age of Virtualization upon us?</title>
		<link>http://www.stevetout.com/oracle-idm/is-the-age-of-virtualization-upon-us</link>
		<comments>http://www.stevetout.com/oracle-idm/is-the-age-of-virtualization-upon-us#comments</comments>
		<pubDate>Sat, 19 Feb 2011 00:03:29 +0000</pubDate>
		<dc:creator>Steve Tout</dc:creator>
				<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[Operations]]></category>
		<category><![CDATA[Virtualization]]></category>

		<guid isPermaLink="false">http://www.stevetout.com/?p=642</guid>
		<description><![CDATA[This week I relished in the announcement here and this Metalink article that Oracle recently made about support for running Oracle on VMware virtualized environments. Then again, for those of us who have been doing the same for awhile now, it&#8217;s not *that* big of a deal. Or is it? Having spent a fair amount [...]]]></description>
			<content:encoded><![CDATA[<div style="height:33px;" class="really_simple_share robots-nocontent snap_nopreview"><div class="really_simple_share_facebook_like" style="width:100px;">
				<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.stevetout.com%2Foracle-idm%2Fis-the-age-of-virtualization-upon-us&amp;layout=button_count&amp;show_faces=false&amp;width=100&amp;action=like&amp;colorscheme=light&amp;send=false&amp;height=27" 
						scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:100px; height:27px;" allowTransparency="true"></iframe>
				</div><div class="really_simple_share_google1" style="width:90px;">
					<g:plusone size="medium" href="http://www.stevetout.com/oracle-idm/is-the-age-of-virtualization-upon-us" ></g:plusone>
				</div><div class="really_simple_share_linkedin" style="width:px;">
					<script type="IN/Share" data-counter="right" data-url="http://www.stevetout.com/oracle-idm/is-the-age-of-virtualization-upon-us"></script>
				</div><div class="really_simple_share_stumbleupon" style="width:px;">
					<script type="text/javascript" src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.stevetout.com/oracle-idm/is-the-age-of-virtualization-upon-us"></script>
				</div><div class="really_simple_share_email" style="width:px;">
					<a href="mailto:?subject=Is the Age of Virtualization upon us?&amp;body=Is the Age of Virtualization upon us? - http://www.stevetout.com/oracle-idm/is-the-age-of-virtualization-upon-us"><img src="http://www.stevetout.com/wp-content/plugins/really-simple-facebook-twitter-share-buttons/email.png" alt="Email" title="Email" /> </a> 
				</div><div class="really_simple_share_twitter" style="width:110px;">
					<a href="http://twitter.com/share" class="twitter-share-button" data-count="horizontal" 
						data-text="Is the Age of Virtualization upon us?" data-url="http://www.stevetout.com/oracle-idm/is-the-age-of-virtualization-upon-us" 
						data-via="" ></a> 
				</div></div>
		<div style="clear:both;"></div><p>This week I relished in the announcement <a href="http://blogs.oracle.com/UPGRADE/2011/01/is_oracle_certified_to_run_on.html">here</a> and this <a href="https://support.oracle.com/CSP/main/article?cmd=show&#038;type=NOT&#038;id=249212.1">Metalink article</a> that Oracle recently made about support for running Oracle on VMware virtualized environments.  Then again, for those of us who have been doing the same for awhile now, it&#8217;s not *that* big of a deal.  Or is it?</p>
<p>Having spent a fair amount of time at the VMware booth at Oracle Open World and witnessed the intense interest in virtualizing everything Oracle, from RAC and Database servers; at the VMware Booth Dave Welch from <a href="http://www.houseofbrick.com">House Of Brick Technologies</a> attests it has had Tier 1 workloads on VMware since 2006 (and seen $ millions of capex/opex reductions), there were no shortage of folks from the audience taking note; to Middleware and as I have discussed <a href="http://www.stevetout.com/oracle-idm/oracle-open-world-2010-wrap-up">Oracle IdM on VMware</a> as well.  Sadly, there are others from various industries who have not even begun to virtualize their Oracle infrastructures due to Oracle&#8217;s previous stance on support running their products on VMware.</p>
<p><div id="attachment_647" class="wp-caption alignright" style="width: 310px"><img src="http://www.stevetout.com/wp-content/uploads/1009402-WS-SnapshotManager-300x254.jpg" alt="VMware Snapshot Manager" title="VMware Snapshot Manager" width="300" height="254" class="size-medium wp-image-647" /><p class="wp-caption-text">VMware Snapshot Manager</p></div>The value proposition for running production loads on VMware was crystalized while still with Oracle Consulting (circa 2007) where my first 2 gigs were assisting clients with their upgrade to OAM 10g.  Both clients had agreed to a 4 week stint for the upgrade.  One company was from the Bay Area, who was running VMWare, and a global beverage company from Atlanta who was not on VMware.  In spite of best laid plans, it&#8217;s always wise to hope for the best and plan for the worst.  During upgrade experiences at the smaller Bay Area company, the issues we encountered were quickly and easily rolled back.  In contrast, the same issue occurred at the larger client not running on VMware, and half days, sometimes entire days were wasted rolling back to a known good state, IN A LAB ENVIRONMENT!  And we could not attribute the failed attempts to the size of the environment either, because one year prior another consultant had spent time documenting and creating the upgrade strategy.  Regardless who&#8217;s to blame for upgrade failures, it&#8217;s a no brainer reverting to a previous ESX <a href="http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&#038;cmd=displayKC&#038;externalId=1009402">snapshot</a> is a huge time saver, especially when modifying schemas on AD which are painfully difficult to remove! </p>
<p>Beyond the benefits of snapshots and virtualization for the Upgrade scenarios there are the extraordinary stories for consolidation itself to be told.  Infrastructure consolidation invariably leads to other interesting possibilities such as cloning (which I talk more about <a href="http://www.stevetout.com/oracle-idm/vmware-shows-its-prowess-cloning-oracle-idm">here</a>) for building out new environments, making your infrastructure portable to make building out cloud infrastructure more efficient, to even being the key to your cloud security, as Art Coviello <a href="http://www.computerworld.com/s/article/9209578/Virtualization_can_be_key_to_cloud_security_RSA_chief_says">talked about</a> at the RSA conference this week.</p>
<p>So in all honesty, I don&#8217;t feel that the announcement from the Evil Empire in Redwood Shores is for me so much as it is for other large companies I know exist out there with sizable physical infrastructures.  I have seen success and failures due in large part to the virtualized environment (or lack thereof) so to encourage those of you who have not gone down that path, that now you have an open doorway to bring your support issues and take another hard look across your IT infrastructure of prime opportunities for consolidation and to better realize benefits from this Age of Virtualization, which arguably is already giving way to the Age of Cloud Computing or Agility as VMware executives like to <a href="http://www.thevarguy.com/2011/02/09/memo-from-vmware-ceo-paul-maritz-to-partners-windows-era-is-ending/">describe it</a>.</p>
<p>With that being said, a huge thanks is due to Oracle, who is now only slightly less evil, for getting out of the way of IT innovations, economic recovery and for giving the power of choice back to the customer.</p>
<p>As always, feel free to leave your comments here in the blog thread.  And if you are in need of assistance or want more resources on virtualizing your Oracle environment with VMware, head over to <a href="http://vmware.com/partners/virtualize_oracle_landscape.html">http://www.vmware.com/oracle</a> for more information.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stevetout.com/oracle-idm/is-the-age-of-virtualization-upon-us/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Oracle Open World 2010 Wrap-up</title>
		<link>http://www.stevetout.com/oracle-idm/oracle-open-world-2010-wrap-up</link>
		<comments>http://www.stevetout.com/oracle-idm/oracle-open-world-2010-wrap-up#comments</comments>
		<pubDate>Tue, 05 Oct 2010 02:16:52 +0000</pubDate>
		<dc:creator>Steve Tout</dc:creator>
				<category><![CDATA[Current Events]]></category>
		<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[VMware]]></category>

		<guid isPermaLink="false">http://www.stevetout.com/?p=501</guid>
		<description><![CDATA[It&#8217;s been a little over a week since OOW, and finally getting back into the swing of things. I should say up front that while I spoke at Oracle Open World, this was not a general session like VMworld, but instead I spoke from the VMware booth at Oracle Open World. Not only was it [...]]]></description>
			<content:encoded><![CDATA[<div style="height:33px;" class="really_simple_share robots-nocontent snap_nopreview"><div class="really_simple_share_facebook_like" style="width:100px;">
				<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.stevetout.com%2Foracle-idm%2Foracle-open-world-2010-wrap-up&amp;layout=button_count&amp;show_faces=false&amp;width=100&amp;action=like&amp;colorscheme=light&amp;send=false&amp;height=27" 
						scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:100px; height:27px;" allowTransparency="true"></iframe>
				</div><div class="really_simple_share_google1" style="width:90px;">
					<g:plusone size="medium" href="http://www.stevetout.com/oracle-idm/oracle-open-world-2010-wrap-up" ></g:plusone>
				</div><div class="really_simple_share_linkedin" style="width:px;">
					<script type="IN/Share" data-counter="right" data-url="http://www.stevetout.com/oracle-idm/oracle-open-world-2010-wrap-up"></script>
				</div><div class="really_simple_share_stumbleupon" style="width:px;">
					<script type="text/javascript" src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.stevetout.com/oracle-idm/oracle-open-world-2010-wrap-up"></script>
				</div><div class="really_simple_share_email" style="width:px;">
					<a href="mailto:?subject=Oracle Open World 2010 Wrap-up&amp;body=Oracle Open World 2010 Wrap-up - http://www.stevetout.com/oracle-idm/oracle-open-world-2010-wrap-up"><img src="http://www.stevetout.com/wp-content/plugins/really-simple-facebook-twitter-share-buttons/email.png" alt="Email" title="Email" /> </a> 
				</div><div class="really_simple_share_twitter" style="width:110px;">
					<a href="http://twitter.com/share" class="twitter-share-button" data-count="horizontal" 
						data-text="Oracle Open World 2010 Wrap-up" data-url="http://www.stevetout.com/oracle-idm/oracle-open-world-2010-wrap-up" 
						data-via="" ></a> 
				</div></div>
		<div style="clear:both;"></div><p>It&#8217;s been a little over a week since OOW, and finally getting back into the swing of things.  I should say up front that while I spoke at Oracle Open World, this was not a general session like VMworld, but instead I spoke from the VMware booth at Oracle Open World.  Not only was it great hanging out with some really cool folks from the marketing teams from VMware (which I never get to do) I also had the chance to speak directly with Oracle and VMware partners and customers about the cool things that me and my team at VMware have been working on over the past 18 months.  It was a throwback to my consulting days at Oracle, which were great, but with the liberty to share more about doing things with VMware than the ordinary Oracle Consultant does.  </p>
<p>My short presentation was focused on helping Oracle IdM customers get a handle on the top pain points that a company might encounter from an operations perspective, and  I offered some insights on the challenges one will face and a VMware specific solution to the problem.  In essence, if you can build your Oracle IdM foundation on VMware vSphere starting Day 1, it will lend itself to dramatic time/cost savings and speed with regards to building out new environments and horizontally scaling those environments as your business and IT infrastructure evolves.  </p>
<p>Also, as an EMC company, VMware employees enjoy a great partnership and access to world-class tools and support for managing the Oracle database, which is the very foundation for Oracle IdM.  As such, another of the practices we use at VMware, which I also discussed in the talk at OOW, is not as much VMware focused as it is on the EMC technology, but it has to be included to paint a complete picture for improving efficiency of your operations environment.  Of course, some of you were quick to point out that EMC&#8217;s SRDF isn&#8217;t the only company to provide block level copy of Oracle data, we happen to think it&#8217;s a really good one worty of your consideration.  For more about this process, you can view <a href="http://www.slideshare.net/gmahler5th/tout-v-mworld2010v10">my VMworld presentation</a> on managing Oracle data with SRDF, or you can get more from your local DBA or straight from EMC, such as EMC&#8217;s own <a href="http://oraclestorageguy.typepad.com">Oracle Storage Guy</a>.</p>
<p>For those of you who didn&#8217;t attend either talk or catch the link on my Twitter post, here is my OOW presentation.  Being only given 30 minutes I could not go into too much technical detail here, so please forgive me.  You can, however, talk with your in-house IdM Architect/Admin or IdM consultant about how you can build your Oracle IdM environment similar to the way I talk about in my presentation.  </p>
<div id="__ss_5255657" style="width: 425px; align: center;"><strong style="display: block; margin: 12px 0 4px;"><a title="Managing Oracle IdM on VMware vSphere" href="http://www.slideshare.net/gmahler5th/managing-oracle-idm-on-vmware-vsphere">Managing Oracle IdM on VMware vSphere</a></strong><object id="__sse5255657" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="355" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=toutoow201010-1285137130503-phpapp01&amp;stripped_title=managing-oracle-idm-on-vmware-vsphere&amp;userName=gmahler5th" /><param name="name" value="__sse5255657" /><param name="allowfullscreen" value="true" /><embed id="__sse5255657" type="application/x-shockwave-flash" width="425" height="355" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=toutoow201010-1285137130503-phpapp01&amp;stripped_title=managing-oracle-idm-on-vmware-vsphere&amp;userName=gmahler5th" allowscriptaccess="always" allowfullscreen="true" name="__sse5255657"></embed></object></div>
<div style="padding: 5px 0 12px;">View more <a href="http://www.slideshare.net/">presentations</a> from <a href="http://www.slideshare.net/gmahler5th">Steve Tout</a>.</div>
<p>In addition to presenting at the VMworld booth I also got a chance to talk to a director at Oracle about collaborating on some white papers for publication on OTN on best practices and configuration specs for building and running Oracle IdM on VMware vSphere.  There is nothing like this that I am aware of, and if there is (please share your stories with me) then this will just make it an official collaboration between VMware and Oracle.  We are just getting started, and I would expect this to be available to the public sometime in Q1 of 2011.  You can follow my blog&#8217;s RSS feed or my <a href="http://www.twitter.com/stevetout">Twitter</a> as that is where I will make the announcement when these papers are available.  Another way is to check www.vmware.com/oracle for the latest updates on this collaboration.</p>
<p>On a final note, I received some some sad news last week on the heels of Oracle Open World that Oracle will be losing Rohit Gupta to run another company in the Bay Area.  Rohit has been around the Oracle IdM space as long I can remember Oracle being in this business (circa 2005) in field enablement and product management.  I got a chance to hear Rohit speak in person at Burton Catalyst this year, as the last speaker to an audience of very thirsty IT guys and a bunch of long winded corporate sponsors, he hit the grand slam with a speed 2 minutes under his allotted time with grace, humor and a technical acumen that&#8217;s refreshing coming from a VP.  Rohit, you will be missed by many and I&#8217;m confident you will succeed famously at BMC as you did at Oracle.  And if not, I&#8217;m sure there could be an open door for you at VMware.  <img src='http://www.stevetout.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p>Have a great week, everybody and feel free to comment here on my blog and get some conversations going about how you&#8217;ve put any of these ideas to use in your environment.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stevetout.com/oracle-idm/oracle-open-world-2010-wrap-up/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Automated Refresh of Oracle Data with EMC at VMworld</title>
		<link>http://www.stevetout.com/oracle-idm/automated-refresh-of-oracle-data-with-emc-at-vmworld</link>
		<comments>http://www.stevetout.com/oracle-idm/automated-refresh-of-oracle-data-with-emc-at-vmworld#comments</comments>
		<pubDate>Fri, 27 Aug 2010 16:34:18 +0000</pubDate>
		<dc:creator>Steve Tout</dc:creator>
				<category><![CDATA[Current Events]]></category>
		<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[VMworld]]></category>

		<guid isPermaLink="false">http://www.stevetout.com/?p=488</guid>
		<description><![CDATA[Do you want to learn how VMware manages Oracle Data and Oracle Identity Management middleware with EMC and VMware technologies? Are you curious how VMware rapidly builds new Oracle OID and Access Manager environments with it&#8217;s own products? I will be in San Francisco at VMworld next week presenting &#8220;Automated Refresh of Oracle Data&#8221; during [...]]]></description>
			<content:encoded><![CDATA[<div style="height:33px;" class="really_simple_share robots-nocontent snap_nopreview"><div class="really_simple_share_facebook_like" style="width:100px;">
				<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.stevetout.com%2Foracle-idm%2Fautomated-refresh-of-oracle-data-with-emc-at-vmworld&amp;layout=button_count&amp;show_faces=false&amp;width=100&amp;action=like&amp;colorscheme=light&amp;send=false&amp;height=27" 
						scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:100px; height:27px;" allowTransparency="true"></iframe>
				</div><div class="really_simple_share_google1" style="width:90px;">
					<g:plusone size="medium" href="http://www.stevetout.com/oracle-idm/automated-refresh-of-oracle-data-with-emc-at-vmworld" ></g:plusone>
				</div><div class="really_simple_share_linkedin" style="width:px;">
					<script type="IN/Share" data-counter="right" data-url="http://www.stevetout.com/oracle-idm/automated-refresh-of-oracle-data-with-emc-at-vmworld"></script>
				</div><div class="really_simple_share_stumbleupon" style="width:px;">
					<script type="text/javascript" src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.stevetout.com/oracle-idm/automated-refresh-of-oracle-data-with-emc-at-vmworld"></script>
				</div><div class="really_simple_share_email" style="width:px;">
					<a href="mailto:?subject=Automated Refresh of Oracle Data with EMC at VMworld&amp;body=Automated Refresh of Oracle Data with EMC at VMworld - http://www.stevetout.com/oracle-idm/automated-refresh-of-oracle-data-with-emc-at-vmworld"><img src="http://www.stevetout.com/wp-content/plugins/really-simple-facebook-twitter-share-buttons/email.png" alt="Email" title="Email" /> </a> 
				</div><div class="really_simple_share_twitter" style="width:110px;">
					<a href="http://twitter.com/share" class="twitter-share-button" data-count="horizontal" 
						data-text="Automated Refresh of Oracle Data with EMC at VMworld" data-url="http://www.stevetout.com/oracle-idm/automated-refresh-of-oracle-data-with-emc-at-vmworld" 
						data-via="" ></a> 
				</div></div>
		<div style="clear:both;"></div><p>Do you want to learn how VMware manages Oracle Data and Oracle Identity Management middleware with EMC and VMware technologies?  Are you curious how VMware rapidly builds new Oracle OID and Access Manager environments with it&#8217;s own products?</p>
<p>I will be in San Francisco at VMworld next week presenting &#8220;Automated Refresh of Oracle Data&#8221; during the <a href="http://oraclestorageguy.typepad.com">Oracle Storage Guys</a> session at <a href="http://www.vmworld.com">VMworld</a>.  Look for Session ID: EA7061 on the topic of <em>Creating an Internal Oracle Database Cloud Using vSphere</em> in your handbook.  I will be sharing how we shaved days off our Environment Refresh processes and significantly reduced error rates using EMC&#8217;s SRDF/TimeFinder and custom scripts managed via PPM workflows to achieve greater levels of efficiency and accuracy.</p>
<p>It will be presented twice, so you can catch this session on Monday or Thursday at the following times.</p>
<p>Monday:   Moscone South Room 308 @ 12:00-1:00 PM<br />
Tursday:  Moscone West Room 2007 @ 10:30-11:30 AM</p>
<p>Also, if you are headed to Oracle Open World in September, look for me at the VMware booth.  I will be there to talk about how VMware, in addition to the EMC/SRDF solution described at VMworld for bootstrapping Oracle DB instances, uses vSphere to clone and build out new Oracle Identity Management environment.  I <a href="http://www.stevetout.com/oracle-idm/vmware-shows-its-prowess-cloning-oracle-idm">blogged</a> about how awesome this is awhile back, but this will give you a chance to hear a 6-month progress update and ask any questions.  Stay tuned for more details on which days and times.</p>
<p>See you there!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stevetout.com/oracle-idm/automated-refresh-of-oracle-data-with-emc-at-vmworld/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VMware shows its prowess Cloning Oracle IdM</title>
		<link>http://www.stevetout.com/oracle-idm/vmware-shows-its-prowess-cloning-oracle-idm</link>
		<comments>http://www.stevetout.com/oracle-idm/vmware-shows-its-prowess-cloning-oracle-idm#comments</comments>
		<pubDate>Sat, 13 Mar 2010 21:55:38 +0000</pubDate>
		<dc:creator>Steve Tout</dc:creator>
				<category><![CDATA[Management]]></category>
		<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[VMware]]></category>

		<guid isPermaLink="false">http://www.stevetout.com/?p=261</guid>
		<description><![CDATA[I grew up in a painting family and was raised by a father who was a skilled crafstman, an expert with a lifelong career in painting.  The thing you would expect, that our house would always have a fresh coat each season, or a fresh paint at all, is far from reality.  It&#8217;s like the [...]]]></description>
			<content:encoded><![CDATA[<div style="height:33px;" class="really_simple_share robots-nocontent snap_nopreview"><div class="really_simple_share_facebook_like" style="width:100px;">
				<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.stevetout.com%2Foracle-idm%2Fvmware-shows-its-prowess-cloning-oracle-idm&amp;layout=button_count&amp;show_faces=false&amp;width=100&amp;action=like&amp;colorscheme=light&amp;send=false&amp;height=27" 
						scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:100px; height:27px;" allowTransparency="true"></iframe>
				</div><div class="really_simple_share_google1" style="width:90px;">
					<g:plusone size="medium" href="http://www.stevetout.com/oracle-idm/vmware-shows-its-prowess-cloning-oracle-idm" ></g:plusone>
				</div><div class="really_simple_share_linkedin" style="width:px;">
					<script type="IN/Share" data-counter="right" data-url="http://www.stevetout.com/oracle-idm/vmware-shows-its-prowess-cloning-oracle-idm"></script>
				</div><div class="really_simple_share_stumbleupon" style="width:px;">
					<script type="text/javascript" src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.stevetout.com/oracle-idm/vmware-shows-its-prowess-cloning-oracle-idm"></script>
				</div><div class="really_simple_share_email" style="width:px;">
					<a href="mailto:?subject=VMware shows its prowess Cloning Oracle IdM&amp;body=VMware shows its prowess Cloning Oracle IdM - http://www.stevetout.com/oracle-idm/vmware-shows-its-prowess-cloning-oracle-idm"><img src="http://www.stevetout.com/wp-content/plugins/really-simple-facebook-twitter-share-buttons/email.png" alt="Email" title="Email" /> </a> 
				</div><div class="really_simple_share_twitter" style="width:110px;">
					<a href="http://twitter.com/share" class="twitter-share-button" data-count="horizontal" 
						data-text="VMware shows its prowess Cloning Oracle IdM" data-url="http://www.stevetout.com/oracle-idm/vmware-shows-its-prowess-cloning-oracle-idm" 
						data-via="" ></a> 
				</div></div>
		<div style="clear:both;"></div><p>I grew up in a painting family and was raised by a father who was a skilled crafstman, an expert with a lifelong career in painting.  The thing you would expect, that our house would always have a fresh coat each season, or a fresh paint at all, is far from reality.  It&#8217;s like the saying <em>cobblers children</em> have <em>no shoes.</em>  As I grew old enough to form my own values and ideals about the future, I vowed to never let my family or my children <em>go without shoes</em> so to speak.  At VMware, we are pursuing the dream of IT As A Service, putting new kicks on our feet, and accelerating the use of virtualization across our own IT landscape.</p>
<p>And virtualize, we did.  I am involved on a crush team who&#8217;s objectives include streamlining and automating the build and refresh of environments using VMware virtualization technology, EMC SRDF and BCV technologies.  Since the very beginning Oracle IdM has ran on VMs at VMware except for RAC, but even now that is changing.   In spite of how compelling virtualization is for businesses and IT, it&#8217;s not as simple as running IdM on a VM.  Having hard-wired references to hostnames and PKI baked into a cloned copy makes &#8220;Instant On&#8221; a stretch of the imagination without taking appopriate steps to transform a cloned copy of say Production to make it operate as a completely separate and independent entity.</p>
<p><strong>Cloning OID</strong></p>
<p>VMware worked with some smart consultants at <a title="Identigral, Inc." href="http://www.identigral.com" target="_blank">Identigral</a> to create a procedure for reconfiguring a cloned instance of Oracle Internet Directory (OID) which is not exactly a supported and documented feature provided by Oracle, but is in any case effective for the purpose of rapid deployment.  This procedure gave the foundation for executing on my vision of clone automation for Oracle IdM that I shared with Identigral consultants.</p>
<p>Oracle&#8217;s OID Product Mgmt team reviewed the solution and suggested (as I would expect) that this is not a procedure to be used for building production instances.  Also, there is the risk that cloning OID will cause some problems with patching and upgrading.  But taking a step back and looking at why we want to rapidly build or refresh an environment in the first place, it&#8217;s for testing purposes, not to build a clean or new production environment.  So we have clearance from Oracle on OID cloning methodology, with the usual caveats.</p>
<p>Testing of the procedure proved its effectiveness so far in 2 of 2 exercises.  So now, we have a cloned VM, running a cloned OID, which is setting the table for either cloning OAM or installing it from scratch, or a hybrid of cloning and re-installing.</p>
<p><strong>Cloning OAM</strong></p>
<p>Cloning OAM is not as easy nor as straight forward of an approach.  There are certainly shortcuts for building any new OAM environment, or refreshing an environment (affecting only user data) but for a company whose ambition or need is to build numerous test instances for whatever reason, the argument for taking shortcuts and even automating to a certain extent is compelling. </p>
<p>To start, as quick as it is to install new servers, and ensuring that there are no corruptions or issues when building the core configuration, the fresh install of OAM servers is a good safe bet.  Once the core foundation is installed, policies and configurations can then be exported from a source, lets say a golden copy from production, and modified to fit the needs of your target environment. </p>
<p>Here is where the black art of Oracle IdM environment management comes into play.  Attempts by Oracle to offer migration tool set has not been received well, so this creates room for Oracle Consulting, and their partners to add value to IdM customers.  Typically, IdM consultants with years of experiences can have an intuitive knowledge about what should be copied from a source environment, how to massage the data, and then import it into the target environment in a manual approach spanning several days depending on the environment complexity.   This is a valuable, and critical competency that any IdM Administrator should have, and of course the organization who has OAM.  Multiply this exercise of say 40 hours by how many environments you plan to use for testing and development in the coming year and then by $125 or more, and you come up with a figure for annualized maintenance costs just for instance management.</p>
<p><strong>Extreme Cloning</strong></p>
<p>Taking the project to an even more extreme level, a person could justify automating the clone procedures by writing their own scripts to export, transform and deploy on the basis that the one-time development costs are less than the annualized maintenance costs.  The ROI formula I came up with looked something like this:</p>
<ul>
<li><em>Approx. number of hours to build OAM manually = x</em></li>
<li><em>Hourly rate of IdM Admin = y</em></li>
<li><em>Number of environments you will build this year = z</em></li>
</ul>
<p>With that you can come up a figure with the following formula:  <strong>Annual instance management cost</strong> = (x*y)*z</p>
<p>In contrast, lets say that we could develop and deploy scripts to automate a large portion of this work. </p>
<ul>
<li><em>Approx number of hours to design and build scripts to automate clone activity = x</em></li>
<li><em>Hourly rate of expert programmer who has 3+ IdM experience = y</em></li>
</ul>
<p>Then we can perform a basic ROI measure that should allow you to calculate your break even point.  Management will need to know how many environments would need to be built in order for investment in clone automation to pay off.  Depending on how aggressive your IdM initiatives are, it may take more than a year of utilizing your new tool set to see any ROI, not to mention that there are opportunity costs that should be factored in.  (E.g. Your expert programmer is going to be taken off of some other high priority project which can be a setback.)</p>
<p>And to make things even more interesting, recent VMware acquisitions add even more technical capabilities that should ultimately help reduce costs and complexity of  instance management.  I&#8217;m looking forward to the assimilation of Spring Source and <a title="Chuck Hollis on Ionix acquisition" href="http://chucksblog.emc.com/chucks_blog/2010/02/vmware-management-takes-a-big-step-forward-.html" target="_blank">Ionix</a> into VMware virtualization platform so we can create and share templates for IdM configuration management.  Imagine configurable templates as a feature of your platform that transparently supports duplicating and managing IdM environments without the risk and cost of custom software, including having all of the appropriate monitoring (E.g. Zenoss, EM grid agents) deployed right next to it.</p>
<p>I&#8217;d love to hear ways you use VMware to make managing and deploying Oracle IdM easier.  Leave comments here in this blog post or send an email to steve at stevetout dot com.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stevetout.com/oracle-idm/vmware-shows-its-prowess-cloning-oracle-idm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Password insanity!</title>
		<link>http://www.stevetout.com/risk-management/password-insanity</link>
		<comments>http://www.stevetout.com/risk-management/password-insanity#comments</comments>
		<pubDate>Wed, 10 Feb 2010 04:50:05 +0000</pubDate>
		<dc:creator>Steve Tout</dc:creator>
				<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[Online banking]]></category>

		<guid isPermaLink="false">http://www.stevetout.com/?p=234</guid>
		<description><![CDATA[Authentication and password policies are the bane of my existence.  I really feel sorry for millions of consumers who have no idea whats going on (exactly) with the crazy and absurd requirements that companies put in place for logging in to view account balances or make payments.  As I have a few ideas about whats [...]]]></description>
			<content:encoded><![CDATA[<div style="height:33px;" class="really_simple_share robots-nocontent snap_nopreview"><div class="really_simple_share_facebook_like" style="width:100px;">
				<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.stevetout.com%2Frisk-management%2Fpassword-insanity&amp;layout=button_count&amp;show_faces=false&amp;width=100&amp;action=like&amp;colorscheme=light&amp;send=false&amp;height=27" 
						scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:100px; height:27px;" allowTransparency="true"></iframe>
				</div><div class="really_simple_share_google1" style="width:90px;">
					<g:plusone size="medium" href="http://www.stevetout.com/risk-management/password-insanity" ></g:plusone>
				</div><div class="really_simple_share_linkedin" style="width:px;">
					<script type="IN/Share" data-counter="right" data-url="http://www.stevetout.com/risk-management/password-insanity"></script>
				</div><div class="really_simple_share_stumbleupon" style="width:px;">
					<script type="text/javascript" src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.stevetout.com/risk-management/password-insanity"></script>
				</div><div class="really_simple_share_email" style="width:px;">
					<a href="mailto:?subject=Password insanity!&amp;body=Password insanity! - http://www.stevetout.com/risk-management/password-insanity"><img src="http://www.stevetout.com/wp-content/plugins/really-simple-facebook-twitter-share-buttons/email.png" alt="Email" title="Email" /> </a> 
				</div><div class="really_simple_share_twitter" style="width:110px;">
					<a href="http://twitter.com/share" class="twitter-share-button" data-count="horizontal" 
						data-text="Password insanity!" data-url="http://www.stevetout.com/risk-management/password-insanity" 
						data-via="" ></a> 
				</div></div>
		<div style="clear:both;"></div><p>Authentication and password policies are the bane of my existence.  I really feel sorry for millions of consumers who have no idea whats going on (exactly) with the crazy and absurd requirements that companies put in place for logging in to view account balances or make payments.  As I have a few ideas about whats going on,  the fact that I have to call into a customer service help desk on almost a monthly basis for a password reset can only highlight that neither customers nor businesses are having much fun.   Banks and other online bill-pay sites seem compelled to make remembering passwords so difficult that I could pull my hair out.</p>
<p><a rel="attachment wp-att-233" href="http://www.stevetout.com/risk-management/password-insanity/attachment/pwd-restrictions"><img class="alignright size-full wp-image-233" title="pwd-restrictions" src="http://www.stevetout.com/wp-content/uploads/pwd-restrictions.gif" alt="so many password restrictions!!!" width="483" height="204" /></a>Here is the password policy of one very large financial institution&#8230; seriously?  I have and use a hand full of passwords for various online accounts which I have used since the beginning of time.  Most people will run out of variations on the common pass*word* that they will begin to form really bad habits, making their online accounts less secure.  Like say, writing passwords down on paper or saving them in a insecure file on my computer (which I do from time to time) undermines the very security that was meant to be in the first place. </p>
<p>Then there&#8217;s my wife&#8217;s headaches of working with the online account tools of a local bank in a suburb of Seattle, that forced her to have password reset codes sent to her cell phone repeatedly because the bank&#8217;s website no longer recognized the browser or PC that she used to login.  That&#8217;s typically a problem when your identity is tightly embedded into the PC or browser via cookies or registry values that is supposed to help prevent unauthorized access.  Over course of several days, using one of several different PCs in our house, she managed to re-verify herself and lock out her account 3 times.  What s dreadful password policy that other smart people undoubtedly have endured&#8230;.  As if we don&#8217;t have enough phone calls to make or things to do in one day. *sigh*</p>
<p> So what&#8217;s the answer?</p>
<p>Listen to your customers!   Balance end-user compassion with account security and privacy mechanisms.  Password policy need not be so complex.  Some solutions, such as Oracle Adaptive Access Manager, work on the back end monitoring login attempts based on signature files and patterns of hacking activity, which in turn can result in a huge boost of compassion for your end-users.</p>
<p>So what are your experiences with insane password policies?  How many passwords do you have?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stevetout.com/risk-management/password-insanity/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My IdM Christmas Wish List</title>
		<link>http://www.stevetout.com/oracle-idm/my-idm-christmas-wish-list</link>
		<comments>http://www.stevetout.com/oracle-idm/my-idm-christmas-wish-list#comments</comments>
		<pubDate>Mon, 21 Dec 2009 22:46:49 +0000</pubDate>
		<dc:creator>Steve Tout</dc:creator>
				<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[VMware]]></category>

		<guid isPermaLink="false">http://www.stevetout.com/?p=28</guid>
		<description><![CDATA[While I actually have enjoyed these items on my wish list for awhile, they are very practical and fresh full of usefullness and insights year after year. I use and would recommend any of the following wish list items to my colleague or friends who make his or her livelihood through professional Identity &#038; Access [...]]]></description>
			<content:encoded><![CDATA[<div style="height:33px;" class="really_simple_share robots-nocontent snap_nopreview"><div class="really_simple_share_facebook_like" style="width:100px;">
				<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.stevetout.com%2Foracle-idm%2Fmy-idm-christmas-wish-list&amp;layout=button_count&amp;show_faces=false&amp;width=100&amp;action=like&amp;colorscheme=light&amp;send=false&amp;height=27" 
						scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:100px; height:27px;" allowTransparency="true"></iframe>
				</div><div class="really_simple_share_google1" style="width:90px;">
					<g:plusone size="medium" href="http://www.stevetout.com/oracle-idm/my-idm-christmas-wish-list" ></g:plusone>
				</div><div class="really_simple_share_linkedin" style="width:px;">
					<script type="IN/Share" data-counter="right" data-url="http://www.stevetout.com/oracle-idm/my-idm-christmas-wish-list"></script>
				</div><div class="really_simple_share_stumbleupon" style="width:px;">
					<script type="text/javascript" src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.stevetout.com/oracle-idm/my-idm-christmas-wish-list"></script>
				</div><div class="really_simple_share_email" style="width:px;">
					<a href="mailto:?subject=My IdM Christmas Wish List&amp;body=My IdM Christmas Wish List - http://www.stevetout.com/oracle-idm/my-idm-christmas-wish-list"><img src="http://www.stevetout.com/wp-content/plugins/really-simple-facebook-twitter-share-buttons/email.png" alt="Email" title="Email" /> </a> 
				</div><div class="really_simple_share_twitter" style="width:110px;">
					<a href="http://twitter.com/share" class="twitter-share-button" data-count="horizontal" 
						data-text="My IdM Christmas Wish List" data-url="http://www.stevetout.com/oracle-idm/my-idm-christmas-wish-list" 
						data-via="" ></a> 
				</div></div>
		<div style="clear:both;"></div><p><div id="attachment_60" class="wp-caption alignright" style="width: 195px"><img src="http://www.stevetout.com/wp-content/uploads/26700704.jpg" alt="Oracle IdM by Marlin Pohlman" title="Oracle IdM" width="185" height="265" class="size-full wp-image-60" /><p class="wp-caption-text">Oracle IdM by Marlin Pohlman</p></div>While I actually have enjoyed these items on my wish list for awhile, they are very practical and fresh full of usefullness and insights year after year.  I use and would recommend any of the following wish list items to my colleague or friends who make his or her livelihood through professional Identity &#038; Access management.  Feel free to leave comments and share your wish list items with those who stumble upon my list.  Thanks in advance.</p>
<p><strong><a href="http://astore.amazon.com/stevetout-20/detail/1420072471">Oracle Identity Management</a> by Marlin Pohlman.</strong>  This is IdM &#038; GRC 101 as far as Oracle is concerned, folks.  It&#8217;s comprehensive in scope and decidedly biased towards the incredible technology from the largest software company in the world.  After giving a nice overview of each technology in Oracle&#8217;s IdM suite, it gives a comprehensive and accessible reference on governance and compliance for multi-national businesses.  A must read for any IdM engineer looking to rise above his or her reputation as IdM Admin, and also for managers looking to get a better grasp of the wide ranging technology in the IdM Suite.</p>
<p><strong>A Subscription to Dr. K&#8217;s blog <a href="http://blog.talkingidentity.com">Talking Identity</a></strong> &#8211; The Dr. is in and he will see you now.  Here&#8217;s another wish that shows my Oracle bias.  The blog contains architectural gems in the world of IdM, and is blazing trails in security and identity issues for cloud computing.  Best of all, it&#8217;s free!</p>
<p><strong><a href="http://www.novell.com/coolsolutions/tools/13765.html">LDAP Browser/Editor v2.81</a></strong> &#8211; Here it is.  The lightest weight LDAP browser/editor on the planet (that I&#8217;m aware of) and it&#8217;s yours for free, assuming you can still find it.  The internet went silent in early 2009 and the publisher&#8217;s original download URL disappeared.  Where did our friend Mr. Gawor go, anyone?  Any ways, the first and last thing I&#8217;d ever need to do in IdM is browse, search and edit basic information like user profile attributes, and the occassional import or export of an ldif file.  There are no schema editing capabilities, but how often does one really need that?  I&#8217;ve been doing this job for 10 years and of all the tools I have used, this is at the top of my list.  </p>
<p><strong><a href="http://www.oracle.com/consulting/library/data-sheets/oracle-unified-method-customer-program.pdf">Oracle Unified Method</a></strong> &#8211; Another one of Dr. Pohlman&#8217;s brain children, OUM is the next best thing to working with Oracle Consulting, although you may need to work with OCS to get your hands on a copy.  This is a wealth of resources to ensure smooth delivery of your IdM projects.  From Detailed Design, to QA, Support and Training, it&#8217;s all in there.  A more or less Oracle flavor of RUP.</p>
<p><strong><a href="http://office.microsoft.com/en-us/onenote/default.aspx">Microsoft OneNote</a></strong> &#8211; Every now and then Microsoft works out something very cool.  Think Windows 7 and Zune HD for example.  Love em or hate em, Microsoft is a part of (most) all our daily lives.  OneNote is one tool that helps me take names and kick butt every single day.  You want a business justification on the mertis of OAM vs. ESSO?  Meeting minutes with in-line commentary?  Technical analysis and post mortem of the latest production outage?  OneNote is an extension of my brain, a place to capture and share all of that unstructured data that is all around.  When it&#8217;s time to compare notes, present ideas or persuade others quickly without writing a book, just <strong>Send > Email Page As PDF </strong> and go on with the rest of your day.  It&#8217;s easy to use, efficient and just amazing tool!  My colleagues rarely (if ever) see anything but PDFs from me, and all by design.  It&#8217;s a game of knowledge management, sharing, presenting and persuading, and for that Office in General and OneNote in particular  is your new best friend.</p>
<p><img src="http://www.stevetout.com/wp-content/uploads/openid-net.gif" alt="openid-net" title="openid-net" width="137" height="51" class="alignright size-full wp-image-67" /><strong><a href="http://openidexplained.com/">OpenID</a></strong> &#8211; The value proposition for OpenID is teriffic!  If you tire of filling out registration forms or challenged by remembering your password for the nth time, then it&#8217;s time for you to get your OpenID.  Not that this hasn&#8217;t been tried before (Passport, anyone?) I can&#8217;t seem to think of any other way than this time it&#8217;s going to be different.  It&#8217;s not owned by Microsoft or any one vendor, is already being used by some very big hitters like Google, Yahoo, Flickr, etc&#8230; and I&#8217;m sure there will be lots more in 2010 that come on board.  This nifty tool will not only save you time and headaches, as someone more career minded in the Identity and Security industry, it will help you stay engaged with and supportive of the issues that the industry faces right now.</p>
<p><img src="http://www.stevetout.com/wp-content/uploads/box_store-workstation7-200x200.jpg" alt="box_store-workstation7-200x200" title="box_store-workstation7-200x200" width="200" height="200" class="alignright size-full wp-image-66" /><strong><a href="http://www.vmware.com/products/workstation/">VMware Workstation 7</a></strong> &#8211; And last but not least, VMware Workstation 7 (and not because I&#8217;m an employee either *grin* ) &#8211; I can step into nearly any business regardless of size, OS, DB or App version and build a slightly replicated environment to test anything from bug fixes, interoperability issues, enhancements or upgrades.  It&#8217;s an invaluable tool for anything from development to QA, and can save an insane amount of time and money on your IdM projects.  I admire any company who bakes this (or VM ESX or Infrastructure) into their development lifecycle.  It&#8217;s an amazing technology!</p>
<p>Merry Christmas, everyone!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stevetout.com/oracle-idm/my-idm-christmas-wish-list/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

