YOUR FEEDBACK
IBM Buys Its Way Out of Antitrust Trouble
Plato wrote: L.L.Bean was never actually a customer of PSI. At most, they we...


2007 West
GOLD SPONSORS:
Active Endpoints
Your SOA Needs BPEL for Orchestration
BEA
Virtualized SOA: Adaptive Infrastructure for Demanding Applications
Nexaweb
Overcoming Bandwidth Challenges with Nexaweb
TIBCO
What is Service Virtualization?
SILVER SPONSORS:
WSO2
Using Web Services Technologies and FOSS Solutions
Click For 2007 East
Event Webcasts

2008 East
PLATINUM SPONSORS:
Appcelerator
Think Fast: Accelerate AJAX Development with Appcelerator
GOLD SPONSORS:
DreamFace Interactive
The Ultimate Framework for Creating Personalized Web 2.0 Mashups
ICEsoft
AJAX and Social Computing for the Enterprise
Kaazing
Enterprise Comet: Real–Time, Real–Time, or Real–Time Web 2.0?
Nexaweb
Now Playing: Desktop Apps in the Browser!
Sun
jMaki as an AJAX Mashup Framework
POWER PANELS:
The Business Value
of RIAs
What Lies Beyond AJAX?
KEYNOTES:
Douglas Crockford
Can We Fix the Web?
Anthony Franco
2008: The Year of the RIA
Click For 2007 Event Webcasts
SYS-CON.TV
TOP THREE LINKS YOU MUST CLICK ON


Novell CEO Messman Postpones Gupta Appointment
Senior VP David Litwack Threatens to Walk According to Sources

Digg This!

David Litwack is responsible for the development and advancement of Novell's secure Web services strategy, a position he assumed in July 2002 following Novell's acquisition of SilverStream Software, a company for which he'd served as president and CEO since 1997. He is also a member of Novell's Worldwide Management Committee. JDJ spoke with him about a range of contemporary computing issues on May 21, 2004. Here is the transcript of this interview.

Goodbye "Middleware," Hello SOA Applications

JDJ: You've worked on PC products in the '80s, then pioneered client/server in the '90s. Since then we've had the Web, and now "Web services." Is it the right term, do you think? For example, an old Powersoft colleague of yours, Mitchell Kertzman, prefers to call the distributed application architecture "client/service." Do you agree - should we be talking about client/service architectures now?

David Litwack: Web services is a technology, not an application architecture. Client/server was comprised of a number of technologies, such as Windows, OO, SQL, ODBC, etc., which together allowed us to build applications in a new way. Web services - as the packaging, description, and discovery model - is only part of the new puzzle. It's the use of "services" as a component-based foundation for applications that is important. At its essence is a clean separation between the source of information and its delivery, which enables a far more flexible and personalized form of application.

There were two things wrong with client/server: the client referred to a specific hardware device and the server referred to a specific back-end system. There was a hard wiring between the two. The goal today is to provision any information or systems, regardless of how they are physically imple-mented, to any audience, regardless of how they connect, in a secure and personalized way based on identity. What we want is to dynamically match the logical service to an identity. In effect, identity/services is a better description of this new architecture.

JDJ:  What about the buzzword of 2004, SOAs?

David Litwack: The industry has struggled a lot more with naming this architecture than client/server, maybe because it's a more comprehensive set of technologies. As I've just described, the essence is the service. So SOA is as descriptive as anything I've heard and seems to have broader acceptance today than any other term. I always try to refer to SOA rather than Web services. In fact, I believe you can be true SOA, without even being SOAP based.

JDJ: Still on Java - what's your position on the JCP - is it the right way to do things?

David Litwack: JCPs are time-consuming and complex, but so are all standards groups. I suspect the hidden agenda when the JCP question is asked is whether the JCP process is "fair," meaning, does Sun bias it? In fact it has been a fair and reasonable process, and Sun has been as reasonable a custodian as can be expected, considering the JCP is not a pure, open standard.

JDJ: Would/could anyone else safely be a custodian of Java? The open source community or IBM?!! How about Novell? ;-)

David Litwack: Tough question. Could Java move from Sun to a more truly open standard? Yes, I think so, with so many organizations already committed to the process. Could it move to open source? Maybe. But remember that you can be an open standard without being open source. Let's separate the two questions. I think Java becoming an open standard would be helpful with some of the industry politics and make Java generally more acceptable to everyone. It would also free up some Java-based efforts from some of Sun's restrictive licensing practices.

As far as open source, Novell has become a huge proponent. However, there are many flavors of open source, some more diffused in the community and some more focused in one or two organizations. Java and J2EE are huge and would require support from some large players. We could start with open sourcing some key pieces, like the JVM, if we could work around Sun's licenses.

JDJ: You have said that few Web services will be open source, since these are frequently tied to strategic, proprietary systems. Can we still expect that the presentation that consumes the Web service will be open sourced, though?

David Litwack: Remember that the essence of Web services is to black box a variety of back ends, to hide their technology. Inside these black boxes there is no standard. They could be mainframes, HP3000, relational databases, EDI, Web sites, SAP systems, and so forth. But on the consumption side, the world is becoming more ordered, with standards such as the Java Portlet spec and XForms. Novell has invested heavily in XForms, working with W3C, because we see it as the missing link that binds XML to presentation. A commonly accepted way of doing things is one of the elements that fosters open source.

JDJ: What's the overall effect on Java of the compelling economics of Linux?

David Litwack at a recent SYS-CON Radio interview. (Photo Copyright: SYS-CON Archives)

David Litwack: Linux is clearly the next market wave. It's driven by the perception that open source has a better economic model for customers and frees them from vendor oppression. A lot of Linux will move into the corporate world in the next few years. Linux will not replace the mass of older systems out there. But there is an ethic about Linux that it will simplify and consolidate. Therefore, I believe that SOA will frequently ride into an organization on the back of Linux.

There are not as many new Java applications being written today as we would like because, frankly, there are not as many new systems being written, period. The adoption of Linux will drive an effort to simplify the historic IT mess, and SOA will be a big part of it. Java and J2EE are excellent environments for implementing SOA.

JDJ: How much closer are we to resolving the security aspects of Web services?

David Litwack: There are three things required to resolve Web services security: a general understanding of the issues; a universally accepted place where the solution will be determined; and acceptance and implementation by the industry. The first has largely occurred. The second involves a consolidation of sometimes competing standards groups. I think by the end of this year, the way will be clear for the delivery of all the key security standards, rapidly followed by commercial implementations by vendors like Novell.

JDJ: What about identity management, is it all sorted yet?

David Litwack: Identity management is yet another really broad term, with many facets. This category has grown up with big players starting from the directory/ metadirectory, and smaller players starting from a variety of areas, like password self-service, workflow-based provisioning, identity-based applications like white pages, and newer areas like virtual metadirectories.

Identity management mirrors SOA in some ways, with a number of moving parts that are fragmented but should really someday integrate to one thing. We're already seeing this consolidation occur, with a number of smaller players recently being acquired.

Ultimately, identity management should be about:

  • Maintaining and administering a single view of identity, across disparate identity stores. This may include multiple directories or application data stores within or across organizational boundaries.
  • Authorizing access based on role or organizational group, either via an administrator, delegate, or user self-service
  • Provisioning resources based on centrally maintained policies or via workflow-based approvals
  • Providing identity-based applications, such as white pages, yellow pages, org charts, skills inventories, etc., in an easily customized way that may also be embedded within applications
  • Auditing and monitoring of all identity-based activities in a way that can satisfy regulatory requirements
It will increasingly become the industry view that this is one integrated whole, and not piece parts.

JDJ: Talking of complexity, is J2EE too complex? If so, what's the best way forward?

David Litwack: I believe that all standards go through three phases. First, the standard demonstrates its value but is immature, missing some of the basics, and we eagerly await the next version. Then the standard matures substantially, with many of the most frequently used pieces becoming robust. The standard is now enterprise ready, but it becomes harder for vendors to implement the much more complex standard, especially now that they have a large customer base to support and migrate. Finally, the standards body spends much of its effort on peripheral issues that a very small percent of the base will use or even understand. This occurs at precisely the time when the standard becomes mainstream and a core set of features are used widely, by mainstream users who hardly know about the more exotic features. At this point, vendors begin to question the need to implement the entire spec.

J2EE is well into the second phase. As the complexity increases, the relevance of incremental features diminishes and the standard starts to stabilize. An interesting side note with J2EE is that in the next year or so, you will see enterprise class, compliant, open source J2EE servers. It's possible, despite Sun's certification practices, that the pressure from the open source community for mainstream enhancements will trump the more theoretical nature of the mature standards committees.

JDJ: Why did Sun's Jonathan Schwartz say "Middleware is history"? Is middleware in fact just beginning? Or is Schwartz right, and end-to-end "systems" will supplant it?

David Litwack: What's in a name? SOA is an inherently middle-tier centric architecture. There's no doubt that in the world of SOA we will have application, integration, and portal servers; content management systems; policy and workflow engines; directories and metadirectories; identity providers; proxies; etc. These are all technically middleware. But as a market category, middleware may very well go away. Why? Because all of these things listed are only a means to an end and, therefore, not what people want to buy. People don't buy carburetors to have carburetors. Carburetors are a means to an end. People buy cars.

What is the equivalent of the car? An SOA application. At Novell, we've been working to bring together all aspects of identity-based SOA into a suite for that reason. The more transparent we can make middleware, the easier it will be to deliver SOA applications. That will be the new category.

  • Senior VP David Litwack Threatens to Walk
  • Novell Narrowly Profitable in Q4
  • Novell Downgraded: Messman Gives Up On Ram Gupta Appointment
  • About Jeremy Geelan
    Jeremy Geelan is Sr. Vice-President of SYS-CON Media & Events. He is Conference Chair of the AJAXWorld Conference & Expo series, of the 3rd International Virtualization Conference & Expo and founder of Web 2.0 Journal, AJAXWorld Magazine and other major SYS-CON titles. From 2000-6, as first editorial director and then group publisher of SYS-CON Media, he was responsible for the development of all new titles and i-Technology portals for the firm, and regularly represents SYS-CON at conferences and trade shows, speaking to technology audiences both in North America and overseas. He is executive producer and presenter of "Power Panels with Jeremy Geelan" on SYS-CON.TV.

    Jaguar wrote: Good Move Mr. Litwack. If the Novell BOD had any balls they would have kicked the MESS-MAN long time ago and appointed Chris Stone as CEO. Messman is ruining the spirit of Novell. The stock is at 6 instead of 20 due to the MESSMAN non-event. This CEO is a fake, absolutely useless. He has been on the Novell BOD since 1986 ( I believe) . When Novell took over Cambridge TP, Messman was asked why Cambridge didn't use any Novell products he replied: "I didn't know they have such great products ( after 15 years on the Novell board). Gimme a break. This man has to go !
    read & respond »
    Novell Nonsense wrote: Good for Mr Litwack - he always was a decent guy. Maybe Stone will have the last laugh after in all in this tawdry corporate tale.
    read & respond »
    Rost Vashevnik wrote: I can not agree more with the advice at the end of the previous comment by Vance Lister : "Whether an institution implements monolithic, client/server, middleware or SOA, make sure the data format is consistent; reusing a data definition will be more cost effective than reusing code." High level of reuse of data definitions can only be achieved if common data dictionaries are used to model and implement databases, middleware, services and user interfaces. The product I am working on - MetaBoss offers facilities to maintain enterprise data dictionaries and reuse data definitions across all systems and layers.
    read & respond »
    Vance Lister wrote: We look to SOA because Middleware has failed us. An enterprise has hundreds of computers on desks and in departments, running vastly disparate applications from many vendors. Middleware exists to get data from one place to another and ultimately gather data for integration. Unfortunately, the cost of middleware, interoperability and integration now costs more than the applications themselves (certainly in the financial world where I work). SOA holds out the hope of reducing the number of applications by providing a single service, enterprise-wide, where duplicate applications previously existed. All SOA enabling environments offer the opportunity to mix and match services from different vendors for use throughout the enterprise. Unfortunately, when vendors offer fifty web services instead of one...
    read & respond »
    Rost Vashevnik wrote: "People buy cars" - is probably referring to people who need cars. People who need middleware will buy middleware. People who need SOA product will buy SOA product and will probably get some sort of middleware within it. So it looks to me that SOA product vendor will need to buy middleware. We have had SOA for years. CORBA and / or COM/DCOM/ActiveX could have been used to implement SOA within organisation for long time. But never before we have heard that middleware is dead. So what is so different about SOAP that now gives vendors right to say that middleware is dead ? Will they not use a database ? Will they not have distributed architectures inside to implement their Services ? Will they not have transactions ? I think they are just trying to "segment" the market and carve up a niche for themselves.
    read & respond »
    JDJ Response wrote: Great question: we asked IBM in our May issue, yes. Here's the relevant exchange, with John Swainson the GM in charge of the entire WebSphere product set... JDJ: [Sun's] Jonathan Schwartz went on record in JDJ as saying "middleware is history." Clearly that wasn't meant literally, but he was saying that end-to-end "systems" will supplant it as a focus. Is the IBM view that middleware, on the contrary, is just beginning? Swainson: Saying that middleware is "history" is laughable. IBM has tens of thousands of customers who need and use middleware for transactions, data management, development tools, systems management, security, and collaboration in a heterogeneous systems environment. The WebSphere platform experienced 12% revenue growth in 2003 over the previous year. The WebSphere platform grew ...
    read & respond »
    Justin Peck wrote: Um, is this the new marching order for the Java elites? "Go out there and tell everyone that middleware is dead so we can push this instead..." First Jonathan Schwartz writes an article in the JDJ, proclaiming the end of middleware (in which he completely failed to tell us why), and now this guy from Novell. Whatever. Have you guys asked what JBoss, BEA or IBM has to say about this?
    read & respond »
    LATEST JAVA STORIES & POSTS
    AJAX and RIA Technology Will Be Free for All: Sun CEO
    'Java's always been a RIA platform - before the world really wanted one,' claimed Sun's CEO Jonathan Schwartz recently, as he reflected on the reinvention of the Java platform as represented by JavaFX. 'What's a rich internet application?' Schwartz wrote. 'It depends on your pers
    Adobe's Kevin Lynch and Microsoft's Scott Guthrie to Keynote AJAX World RIA Conference & Expo
    Two of the biggest launches in Rich Internet Application history took place in 2007/2008 when Adobe launched AIR 1.0 in February '08 and Microsoft launched Silverlight (September '07). At the 6th International AJAXWorld RIA Conference & Expo in October SYS-CON Events is delighted
    Quest Software's JProbe Now Available as Eclipse Plug-In
    Quest Software announced the latest release of its Java profiler, JProbe 8.0, which is now offered as a plug-in to the Eclipse Java Integrated Development Environment (IDE). The release of this capability aligns with the increased adoption of the open source development. Launchin
    What Does the Future Hold for the Java Language?
    Before Java I was a Smalltalk guy. I remember switching from one language to the other and the tipping point that you reach when you've mastered the new language and how many months it takes, not to mention the years, to do really good design and know-how, which patterns to apply
    White Paper: "Ensuring Code Quality in Multi-Threaded Applications"
    Today, the world of software development is presented with a new challenge. To fully leverage this new class of multi-core hardware, software developers must change the way they create applications. By turning their focus to multi-threaded applications, developers will be able to
    AccuRev and Rally Software Partner to Scale Agile Software Development Best Practices
    AccuRev and Rally announced a technology partnership that will integrate AccuRev software change and configuration management (SCCM) with Rally's Agile lifecycle management solutions. The combined solution will provide a platform to manage multiple Agile processes and ongoing cus
    SUBSCRIBE TO THE WORLD'S MOST POWERFUL NEWSLETTERS
    SUBSCRIBE TO OUR RSS FEEDS & GET YOUR SYS-CON NEWS LIVE!
    Click to Add our RSS Feeds to the Service of Your Choice:
    Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
    myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
    Publish Your Article! Please send it to editorial(at)sys-con.com!

    Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021

    SYS-CON FEATURED WHITEPAPERS

    SPONSORED BY INFRAGISTICS
    SOA in a JVM: OSGi Service Platform - A Dynamic Component System for Java
    There are many forces that influence technological evolution. After a decade of building enterprise
    AJAX and Enterprise RIA Tools - JSF, Flex, and JavaFX
    2008 is going to be an important year for Rich Internet Applications. Most organizations are deliver
    Final Voting Phase on OpenAjax Browser Wishlist
    The OpenAjax Alliance is developing an Ajax industry wishlist for future browsers, using a dedicated
    AJAX World RIA Conference News - Netflix UI Guru To Present on Crafting Rich Web Interfaces
    In every field of design one of the first things students do is learn from the work of others. They
    Infragistics Releases CTP UI Components for Microsoft Silverlight Beta 2
    Infragistics announced the availability of two Community Technology Preview (CTP) User Interface (UI
    Yahoo User Interface 2.5.2 Released
    The YUI development team has released version 2.5.2; you can download the new release from SourceFor
    ADS BY GOOGLE
    BREAKING JAVA NEWS
    XS2Theworld's Speaking Travel Guide Wins MCA 2008 Award