Well didnt get the concrete answer but still would like to give points to paranrmastic.
Main Topics
Browse All TopicsHi,
I am trying to get more knowledge about the ILM 2007 ,which can be used Identity management and Smart card/Certificate mgt.
1)From Identity Management part : I can understand that it can be used for identity synch , password synch etc from different systems e.g. between diff forest or share info e.g. bet AD and SQL.
Q: Does anyone has done it in practice (No theories or book examples) and if yes then can you pls tell me in practice what exactly you did and what sort of applications you used to share date between.
2)Certificate and Smart Card mgt : Well again if someone can tell me how they implemented it and with what product etc.
Thanks
M.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Business Accounts
Answer for Membership
by: ParanormasticPosted on 2009-03-18 at 11:52:52ID: 23922208
Based on a lot of the questions I answer around here, I would not expect high usage for ILM for what you are looking for- I would keep this open for a couple days or so, but honestly if you are looking for real world usage examples and how it would relate to your environment in particular, I would recommend talking to MS and asking for case studies or references for that product.
What I can tell you is that if you aren't a larger business - e.g. well over a thousand smartcard users, then the value of such a product is more questionable, especially considering the 15k initial purchase plus more per license (I forget the exact amount, but that adds up quickly). The value is the smartcard management interface and/or if you need a metadirectory for mixing AD with another LDAP (another AD forest or some other LDAP environmnet). If you do not need to share user account information with another directory, then smartcard management would be the only real use.
For smartcard (SC) management, a hundred or two can usually be managed effectively using a spreadsheet or a small database, however larger companies that issue more than a dozen or two cards per day will quickly realize the value of a card management system (CMS), of which there are very few options (MS ILM, activeidentity activID, and intercede myid - there may be a couple newer players in that market, but I wouldn't say any of them offer more than basic service... many other companies will resell one of the three mentioned products). If an employee needs their card revoked, suspended/unsuspended (they forgot it at home), or replaced this offers a central place for issuance, tracking, management, and maintenance, and revocation.
Technically, in older versions the SC part was handled through CLM but that was integrated into ILM2.
I haven't used the ILM product, but have researched it. I used to do support for one of intercede's resellers when at a smartcard company. Without knowing the intricities of this product, this is pretty much how this type of product gets used. The price tag usually scares people away - its unfortunate that there isn't a more economical CMS that is full featured for companies that aren't massive to sweep that cost under the rug, however the development lead time on such a product is many years coming from a number of very experienced developers.