No vitriole, just observations... :-)

IAA is the fundemental tenant of modern information delivery
architectures.  Whatever/whoever is the gatekeeper of that process is
ultimately in a position to control the whole delivery stack.

Kerberos was a brilliant piece of engineering.  Well ahead of its time
with respect to an understanding of what would be critical for highly
mobile user's in a non host-centric authentication model.

It has been readily apparent since the late 1990's that it was only
one piece of the puzzle.  As Henry so aptly noted the concept of
authorization was the larger and in some ways more practically
important piece of the puzzle.

The open-architecture community never developed a holistic view of
IAA.  Authentication and authorization needed to be architecturally
wedded but this never occurred until Microsoft stepped in and filled
the void.  That effectively ceded the most critical element of modern
information delivery architectures to proprietary control.

The Open-Source community responded in typical fashion by moving to
create a functional clone of the AD model.  Great and inspired
engineering which ultimately indemnifies the position of the pundits
that OSS replicates rather than innovates.

History has consistently demonstrated the folly of attempting to
compete on a chessboard where someone else can move the pieces at
will.  Unlike WINE the field of IAA won't tolerate a 95% solution.

IMHO of course.

Now I'm off to push snow.

Best wishes for a pleasant weekend to everyone listening.


