NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 CIO BlackBerry News and Tips
 CIO Research and Analysis
 CIO Microsoft
 CIO Insider
 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 


Mon, Jun 2, 2008 22:13 EDT

What Should IT Managers Know About Open-Source Licensing?

Topic: IT Organization Management

Blog: Executives Online

Current Rating: 5 Comments: 9

People who are themselves active in the open-source community give a lot of attention to licensing. When we wrote recently about a new Cisco messaging protocol, most of the Slashdot discussion and article contents were about the company's choice of open-source licenses. Similarly, it was mainly techies who seemed to get worked up when we wrote about the GPL v3 advantages and disadvantages.

However, I'm not sure if IT managers who are interested in adopting open-source software are paying as much attention to licensing and legal issues. And, arguably, they should be up-to-date on the subject.

So, what do you all think are the key issues that managers need to be aware of? For those who do care... how should they consider the license used? What license models can be trusted by IT? How open source is the dual license model?

Which of the various licensing models do you think will win out over time: GPLv3, AGPL, something else? Which should? When has a new license crossed the chasm?


You do not have flash or javascript support.
Average (3 votes)
5
 
 
Tue, Jun 3, 2008 5:01 EDT
Posted by: Matt Aslett
Rating: 70

that licensing is a bigger consideration for techies than it is for business managers, and it is important to get the issues into perspective. As Ira Heffan wrote yesterday: "If you are planning to use the open source software internally as a stand-alone application and are not going to distribute it, most likely [the license] will be compatible, but still worth taking a look."

All organizations should have processes in place for evaluating contracts and licensing terms, and these should also be used to evaluate open source software, but unless an organization is planning to modify and distribute the software, open source is not necessarily deserving of special attention.

The issue of contribution is covered by today's other question.

 
Tue, Jun 3, 2008 10:02 EDT
Posted by: rongula
Rating: 90

If an IT manager is looking to purchase a technology or service based on an open source technology, they should make sure that their procurement and legal groups are brought into the discussion as early as possible.

The larger your organization is, the more likely there will be some sort of clause in any type of terms and conditions attached to a purchase order that would be used to buy technology or services from a solution provider that makes use of open source.

If there is a desire to purchase open source products, then working with your legal and procurement groups before you ring a vendor into the conversation can be more effective then letting your vendor of choice do the negotiation.

Ron Gula
CEO, Tenable Network Security
http://www.tenablesecurity.com
http://www.nessus.org

 
Tue, Jun 3, 2008 12:57 EDT
Posted by: Mike Milinkovich
Rating: 60

Framing the question in terms of AGPL and GPLv3 implies that variations of the GPL are the only licenses that matter. Which is a shame because if open source ever settles into a single licensing model we have collectively lost a large part of what is important about open source: diversity. Diversity of community and diversity of business models. And a mono-culture in open source does not sound any more attractive to me than a monopoly in proprietary software.

Open source licenses to a very large degree determine the business models of the companies that use them. Companies that select the GPL and its variants are typically following the dual-license model so successfully pursued by MySQL. Venture-backed companies are attracted to this model because it allows them to maintain complete control over their IP, simultaneously offer a commercially licensed variant and potentially foster a community around their code. The question of course, is why do enterprise buyers elect to purchase the commercial version? For many of them it is simply because their legal departments do not want GPL-licensed code in their software stack above the Linux operating system watermark. They would rather pay for commercial licenses. In that context, comparing GPLv2, GPLv3 and AGPL is really comparing different varieties of apples, not apples and oranges.

Because the IT industry hype machines largely runs based on what’s happening in the startups, there is a perception that “open source business” is settling around the GPL and dual-license model. But the fact is that if you look outside startups, what you find is very different. If your enterprise uses commercially licensed software such as IBM Websphere, BEA (now Oracle) Weblogic or SAP Netweaver Studio to list just a few examples, your enterprise is using open source. All of those products make liberal use of code from Apache (ASL) and/or Eclipse (EPL) amongst others. The difference is that the IP due diligence and the license compatibility checking was all performed by the vendor, rather than asking the enterprise to take on the role of both system and license integrator. In all of those cases, the companies shipping commercially licensed products make significant contributions back to the communities from which they take code. In fact, in many cases they collaborate with their direct competitors in order to build open source platforms, and then compete with their differentiated products in the marketplace.

The point is that you cannot separate licensing issues from business models. The two are highly correlated in the open source world. And “open source business” is a much larger conversation than GPL variants and which venture-backed open source startups are going to survive in the long term.

 
Tue, Jun 3, 2008 12:59 EDT
Posted by: lilatretikov
Rating: 83.3333

Open Source often gives you more choices in how you may use the software. And that is probably one of the main reasons there is so much ado about the licensing. Consider the following questions for your specific use case scenario:


Is your organization planning on using the Commercial or the Community/Open Source Edition of the software (i.e. which of the licenses apply in a dual-license model that is adapted by many Commercial Open Source vendors)?


If you plan on using the Commercial Version, then it is likely you will be dealing with a Commercial License.


If you plan on using the Community/Open Source edition then you are likely to be governed by the Open Source version of the license. As Matt mentioned above, if you use the software in a contained fashion, i.e. no redistributing, incorporating or re-packaging, you are likely to be safe. Some of the licenses covering Community Editions make specific provisions for modifying and extending the code base, but pragmatically protect from more invasive revenue-generating actions like branching and re-distributing.


Of course, Open Source software is distributed under a range of licenses, ranging from GPLv3 to BSD. The choice is often particular to the nature of the software itself and the goals behind the project. Viral licensing (like GPLv3) is critical for consumer-ready applications, while BSD-type licensing may be used by more infrastructure/system vendors and non-commercial groups. The question goes back to how a given company applies its Open Source strategy: is is at the core of the business, a lead generator, a market share-driver, a way to build a community, etc. Each goal may require a unique set of parameters, and therefore a modified license.



For the IT manager in charge of purchasing however, it is always critical to understand the license terms, regardless whether it is an Open Source or a Commercial license. Open Source by the definition is no more or less dangerous, but it opens doors to possibilities that Commercial software just does not present (since, well, you can’t see and then re-use the code!). So with any software you are considering, do a once-over with legal on it.

 
Tue, Jun 3, 2008 12:59 EDT
Posted by: johnpowell
Rating: 90

At Alfresco we have gone through several permutations of open source (OS) licensing before settling on GPL v2. Why, you might ask, didn’t we start with GPL v2 – which is the most popular OS license?

I think this really reflected both the development of our thinking and our confidence in OS as well as concerns from “advisors” about how enterprises would react to GPL.

The reality we came to realize was that the OS business model works if all the non-value added activities can be minimised i.e. maximum value can be delivered to the customer for the minimum amount of effort.

Licensing discussion have no added value as far of the performance and operation of the software and so Alfresco settled on the GPL simply because it is the most common and best understood license and for us has dramatically reduced these non-core conversations. This in turn benefits our customers as we can grow and scale faster.

John Powell
CEO, Alfresco Software
http://www.alfresco.com

Post new comment

* Subject:
* Username:
* E-mail:
The content of this field is kept private and will not be shown publicly.
Homepage:
* Body:
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <img> <blockquote> <strike> <p> <br>
  • Lines and paragraphs break automatically.
More information about formatting options

* Denotes required field.

About this Blog

Our visiting guests discuss the topic of the week.

Start a Conversation
Click to post

Got something to say? We want to hear it! Click the Post button to get started. GO»

EXPERT ADVICE
See our roster of experts.

Advice & Opinion from more than 113 of IT's most insightful thinkers.

  PARTNERS       WEBCASTS    
 

Windows 7 Webcast Series

There's a lot of buzz about Windows 7 out there. Each month in our webcast series, listen to analysts and customers discuss how Windows 7 and the Windows Optimized Desktop is impacting large companies around the world. Learn how they evaluated Windows 7, including the cost of deployment, deployment strategies, and tangible benefits.

Sponsored by Microsoft  Listen to on-demand Recordings »

 

Service Level Management Best Practices Life Cycle Overview - Improve Service Levels

Best practices for Service Level Management (SLM) is a process for consistently meeting customer requirements and delivering on IT's promises. See the steps required to ensure high-quality SLM.

Sponsored by Compuware  Read this White Paper »

 

Keeping Your Members Safe from Online Scams and Predators

In order to keep fraudsters out, romance sites must deploy effective solutions that look at information independent of what is supplied by users. A device fingerprinting solution such as iovation ReputationManager™ provides unique insight into the computers being used to create multiple accounts and exposes hidden device-account relationships that identity-based fraud solutions often miss.

Sponsored by iovation  Read this White Paper »

Resource Alerts

Get instant email notifications by topic when white papers, webcasts, and case studies are added to our library.

Resource Alerts

Get instant email notification when white papers, webcasts, and case studies are added to our library. Don't just be up-to-date—be up to the minute with our new Resource Alerts.

Defend Against Blended Threats: What You Need to Know

Blended Web and email threats are becoming increasingly complex and represent a huge...  View Now »

 

Prescriptive Actions to Reduce Risk

In this Webcast, learn best practices for effective systems management in a heterogeneous environment and keep client systems cost under control.   View Now »

 

Webcast- Vantage 11: Redefining Application Performance Management

Compuware's latest release, Vantage 11, is a major advance in end-to-end application performance management--bringing together proactive issue identification, quantification of business impact and problem resolution into a single solution. Tune in to learn how Vantage 11's top-down approach helps you make better decisions and dramatically lower operations costs.  View Now »

Resource Alerts

Get instant email notification when white papers, webcasts, and case studies are added to our library. Don't just be up-to-date—be up to the minute with our new Resource Alerts.

 
NEWSLETTER

Sign-up for the Blogs & Discussion Newsletter

 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Return on Information: Google Enterprise Search pays you back. Get the facts.

VMware. The source for Business Infrastructure Virtualization.

ShoreTel tells businesses to untangle from competitors' complexity and turn to its brilliantly simple UC solution

See how AT&T can help protect your network.

Streamline IT Costs. Boost Performance with WAN Optimization.

Build your 1st app FREE with Force.com

TDWI checklist helps define data readiness for analytics. Download report.

A Clear View Toward Virtualization

Virtualization Technology as a Business Solution

The rules of infrastructure management just changed.

A Clear View Toward Virtualization

Interactive Q&A helps you discover key ways to maximize IT assets.

Ready to virtualize tier one applications? Check your virtualization maturity.

Think you can't afford a Cisco Switch? Cisco Catalyst Switches are now more affordable.

Five minute business analytics assessment. Immediate results.

The Case for Investing in Business Analytics Technology. Read white paper.

Upgrading to VMware vSphere with vWire

Top 10 Lessons Learned for Corporate 3G Mobile Broadband Deployments

CRM Built for IT: The Executive Guide to Selecting CRM that Meets IT Needs

Return on Information: Google Enterprise Search pays you back

ROI of Application Delivery Controllers

Making Consumer Two-Factor Authentication Simple and Cost-Effective

Mining the Cloud to Ease the Enterprise Compliance Burden

Solve Five Key IT Security Challenges with Cloud-Based Authentication

White Paper: Right-Sizing Your Power Infrastructure

AT&T Synaptic Storage as a Service. Expand on demand

Trend Micro ranked #1 against real-world malware. Read more.

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

Top Five CIO Challenges

Read the RSA report: Security for Business Innovation

64-page prescriptive guide to security, compliance, and IT operations.

Increase UPS efficiency without sacrificing protection.

eZine: A Roadmap to Reducing IT Complexity

Reduce risk, gain agility. See how Progress can help your business.

Virtualization Technology as a Business Solution

eZine: A Roadmap to Reducing IT Complexity

World-class trading technology solutions from NYSE Technologies.

If You're Paying for Telecom, You're Paying Too Much. Contact Asentinel Today.

Trade-In your old printer and save up to $1,000 plus free recycling!

infoBOOM! - The Mid-Sized Company CIO's Exclusive Community

Live Webinar: Applying Business Analytics. Click here to learn more

Removing Barriers To Better Server Virtualization Efficiency

4G Revisited. The Continued Evolution of Wireless Mobility.

What's Next for Enterprise Resource Planning?

Maximizing website Return on Information with high-quality search

Gartner Magic Quadrant, Application Delivery Controllers 2009

Authentication as a Service by Forrester Research

Cloud-Based Authentication for Next-Generation Extranets

Cut Costs & Green Your IT Operations with PC Power Management

White Paper: 4 Customer Service Myths