IPSIE is a profile of existing standards, and a challenge today is that people might do something like, oh, well, I've got single sign-on, I have SSO, but what exactly do I have? There are so many settings in SAML and somewhat in OpenID Connect that it's hard to know whether you have something that's secure or not. And so the objective of IPSIE is to set some different levels, both for session lifecycle, which is login, and terminating a session, as well as identity lifecycle, which would be managing the account, who has access to what provisioning, deprovisioning.
And so IPSIE is setting, creating, defining different levels, and then what exactly do you need to configure to have those different levels? So today, organizations need to have their own security profile of exactly what do they mean by SSO, what do they mean by account lifecycle. Each one of those is different, which is challenging for vendors, and the enterprise specification could be incomplete, and then the vendor is trying to figure out and guess what might be happening there. So IPSIE just makes it clear and crisp.
Here's how we do something for different levels of security and control so that people aren't guessing and making things up. Well, one of the challenges in a protocol such as SAML is it's actually a framework, and so there's not any compliance tests to know, am I compliant with SAML? You configure it and you test to see whether it works or not. With IPSIE, because we're specifying all the different settings, a vendor can have a compliance test and you know whether the implementation is compliant or not.
And it specifies both what the Z-Identity servers need to do as well as what the application needs to do. And so the problem that was addressing is people would have things improperly configured that potentially led to security breaches because something wasn't set up, or the server would go down because something wasn't set up correctly. And so IPSIE looks to simplify everything and fill in the gaps of profiling the existing standards so there's a view around what do you implement to make things work. So because it specifies different levels, there isn't all the different dials to choose.
The dials are pretty much all set for you for most of the settings for OpenID Connect, for SAML, and for SCIM. And then there's a new protocol, OpenID Provider Commands, which is the corollary to SCIM or OpenID Connect that myself and Carl McInnes, who's both of us are active in the IPSIE working group, but we've proposed that as yet another way of doing identity lifecycle management. And so it just makes it clear it's most of the things work if you're IPSIE compliant. They will just work together right away without you having to do very much configuration, hopefully.
So today people should probably track, you know, we're looking for as much feedback from practitioners on the standards of like, which things do we need to specify? What's underspecified? What are some of the challenges that people in the field have? And we're looking for that kind of feedback as we work on specifying IPSIE to make sure that we've covered all those things. And we're queuing up to have an interop test early next year. It's still early, there's nothing to specify here. But knowing this is coming along, will help practitioners if they're aware of it, they can start to ask for it.
But the key call to action right now for a practitioner would be to look over the specs and see other things are missing or other things that are over specified. Any other kind of feedback to make that what we end up with is something that's going to work well to solve, you know, a practitioner, you know, an implementer's problems. So we're still early in IPSIE, none of the IPSIE profiles have been standardized. So now there's still another year or two of work. So it's hard to see what might happen after that.
There's still currently there's a draft for IPSIE identity lifecycle on for OpenID Connect. So we still need to work on drafts for levels two and three. There's a draft for SCIM identity lifecycle one, but there's still work for two and three of those as well as opcommand. So we're still very early. So lots of stuff to do, just even on what we're working on today. Love to go and have people go and look at the standards and look the documents and provide feedback, if it makes any sense to them as to what they could do to help.
Between this interview and when the talk is, there's probably going to be some more developments. And so there'll probably be some new things at that point as well. Transcribed by https://otter.ai