COMMENTARY--Thursday was a watershed day for Web services.
Microsoft, IBM, and VeriSign have submitted WS-Security, a group of Web services security specs first announced last April, to the OASIS standards group. The growing list of all-star players that have already agreed to serve on the OASIS technical committee includes BEA, Cisco, Intel, Iona, Novell, RSA, SAP, and--drum roll, please--Sun Microsystems.
For those who've watched the promise of Web services falter in the face of the often vitriolic Microsoft-Sun rivalry, the news couldn't be more welcome. Bill Smith, Sun's director of Liberty Alliance technology (and a past president of OASIS) sees the decision to submit WS-Security to OASIS as an unmistakable olive branch from Microsoft. "We were surprised and very pleased that we were approached to participate," he says. "You can expect to see us engaged very heavily."
Just as important as the players involved, however, is the decision by Microsoft, IBM, and VeriSign to ensure WS-Security will be royalty-free. Explicitly, no party will be able to collect licensing fees from the use of WS-Security, a stipulation that Smith told me was a prerequisite for Sun's participation. He believes the proposed royalty-free license is "sufficient in all regards. Had they not done that, we would not have participated."
"I hope you see from the list of participating companies that this is meant to be an industry-inclusive type of activity," stresses Bob Sutor, IBM's director of e-business standards strategy. However, Sutor downplays the political implications of choosing OASIS, arguing that the standards organization was selected mainly for its history of evangelizing XML directly to business users. But it's hard to imagine a stronger message to the industry that the Web services "movement," as IBM likes to call it, is determined to rise above petty differences.
And what about the good old W3C? Previously, Microsoft and IBM submitted the basic Web services protocols, SOAP and WSDL, to the W3C for approval. Steven VanRoekel, director of Web services technical marketing for Microsoft, is careful to note that "this is not a departure from the W3C in any way," contending that the W3C will almost certainly be on the receiving end of other Microsoft standards proposals--and that OASIS' previous security work simply made it a more appropriate choice this time around.
ZDNet