Identität and Zugang — Keycloak, Vaultwarden, YubiKey, Nitrokey
Machine-supported translation — for legal precision please consult the German master version.
In three sentences
Identity & Access Management (IAM) ist eine Schlüsselkomponente jedes sovereign Stacks. OSS-Lösungen: Keycloak (Red Hat, OIDC/SAML SSO), LLDAP (lightweight LDAP), Authelia (Forward-Auth). Passwort-Manager: Vaultwarden (Bitwarden-kompatibel, self-hostable). hardware tokens: YubiKey (USA, but Hardware), Nitrokey (Deutschland), SoloKey (Open-Source).
Mechanics
Keycloak bietet vollständiges IAM mit OIDC, OAuth 2.0, SAML, LDAP-Federation, MFA. LLDAP ist die schlanke Schweizer Variante (im Politiq-Wiki als Auth-Quelle eingesetzt). Authelia ergänzt for Forward-Auth-Setups mit Traefik/Nginx.
Vaultwarden ist die selbst-hostbare Re-Implementation des Bitwarden-Servers in Rust — kompatibel mit allen Bitwarden-Clients. YubiKey ist Hardware-Authentifikator (FIDO2/U2F, OTP, OpenPGP, PIV); Firmware proprietär, Bedrohungsmodell akzeptabel. Nitrokey and SoloKey sind Open-Hardware-Alternativen aus Europa.
What this means for Switzerland
Im Politiq-Wiki-Stack ist LLDAP die zentrale Auth-Quelle. Schweizer KMU and authorities setzen Keycloak and Vaultwarden zunehmend ein. Nitrokey ist europäische Alternative zu YubiKey, mit weniger Tooling-Reife, but höherer Hardware-sovereignty.
Logical conclusion
IAM-sovereignty ist machbar and reift schnell. hardware tokens sind ein wichtiger Bestandteil — die Frage YubiKey vs. Nitrokey ist ein Trade-off between Tooling-Reife and Open-Hardware-sovereignty.
Implications for legislation
Note: The following points are recommendations from the FADS draft (Section 6) — not current law, but proposals for future Swiss legislation.
The FADS proposal (Art. 15-20) requires for staatliche Identitäts-Infrastrukturen Open-Source-Lösungen and hardware tokens mit auditierbarem Firmware-Pfad.