Zum Inhalt
Verein in Gründung
Pilotbetrieb

Diese Plattform befindet sich im Pilotbetrieb. Trotz sorgfältiger Prüfung können Inhalte und Funktionen Fehler enthalten. Bitte überprüfe wichtige Angaben anhand der verlinkten Originalquellen.

SW-Version alpha 0.41
Darstellung: System
Sprache: DE

Identität and Zugang — Keycloak, Vaultwarden, YubiKey, Nitrokey

Machine-supported translation — for legal precision please consult the German master version.

In three sentences

Identity & Access Management (IAM) ist eine Schlüsselkomponente jedes sovereign Stacks. OSS-Lösungen: Keycloak (Red Hat, OIDC/SAML SSO), LLDAP (lightweight LDAP), Authelia (Forward-Auth). Passwort-Manager: Vaultwarden (Bitwarden-kompatibel, self-hostable). hardware tokens: YubiKey (USA, but Hardware), Nitrokey (Deutschland), SoloKey (Open-Source).

Mechanics

Keycloak bietet vollständiges IAM mit OIDC, OAuth 2.0, SAML, LDAP-Federation, MFA. LLDAP ist die schlanke Schweizer Variante (im Politiq-Wiki als Auth-Quelle eingesetzt). Authelia ergänzt for Forward-Auth-Setups mit Traefik/Nginx.

Vaultwarden ist die selbst-hostbare Re-Implementation des Bitwarden-Servers in Rust — kompatibel mit allen Bitwarden-Clients. YubiKey ist Hardware-Authentifikator (FIDO2/U2F, OTP, OpenPGP, PIV); Firmware proprietär, Bedrohungsmodell akzeptabel. Nitrokey and SoloKey sind Open-Hardware-Alternativen aus Europa.

What this means for Switzerland

Im Politiq-Wiki-Stack ist LLDAP die zentrale Auth-Quelle. Schweizer KMU and authorities setzen Keycloak and Vaultwarden zunehmend ein. Nitrokey ist europäische Alternative zu YubiKey, mit weniger Tooling-Reife, but höherer Hardware-sovereignty.

Logical conclusion

IAM-sovereignty ist machbar and reift schnell. hardware tokens sind ein wichtiger Bestandteil — die Frage YubiKey vs. Nitrokey ist ein Trade-off between Tooling-Reife and Open-Hardware-sovereignty.

Implications for legislation

Note: The following points are recommendations from the FADS draft (Section 6)not current law, but proposals for future Swiss legislation.

The FADS proposal (Art. 15-20) requires for staatliche Identitäts-Infrastrukturen Open-Source-Lösungen and hardware tokens mit auditierbarem Firmware-Pfad.

Further reading

Sources

  • keycloak.org, github.com/lldap/lldap, authelia.com — Link
  • github.com/dani-garcia/vaultwarden — Link
  • yubico.com, nitrokey.com, solokeys.com — Link