Keys on the board¶
Before the move, the Home’s identities hung on the iron key board in the entrance hall, and the board was inside the tenant. Entra ID was the identity for Microsoft 365 and for nothing else. Bestiary kept its own forty-seven accounts, nine of them suspended eighteen months ago and not deleted since. Covenant kept its own, with MFA optional and forty per cent of users taking the option. The Great Ledger kept its own at the Consortium, three of them belonging to people who no longer worked at the Home. Thirty-seven per cent of the tenant’s accounts had no second factor, three administrative accounts had only a password, and of the two Global Administrators one had been gone for fourteen months and still held a key to everything. Mrs Clodpull, who asks every arrival whether they know where they are, had been looking at the board with deep suspicion for some time. The scraps for this layer say: an identity provider is the one landlord that lets the others in, so it cannot be a tenant of any of them.
The counted board¶
The Entra ID audit was the first job, and its findings came first. Guest accounts
from a collaboration four years ago, status unknown. Service accounts named after people who had moved on. Three
accounts that were the same contractor under three spellings. The Covenant consultant’s account, created to set up the
Events module, never given a second factor and never removed. A reception@ and a volunteering@ address whose
password reset flow went to a shared inbox. The MFA rollout had started, stalled and
restarted, and the Conditional Access policies existed in draft. None of
that was negligence. It was the archaeology of staff changes that happened before anyone built an
offboarding process.
Walking out¶
The former Global Administrator’s account was disabled first, sessions revoked, before any committee, on the grounds the privileged access page gives: the account belonged to someone who did not work there, held the highest access in the tenant, and nobody knew whether its password had walked out the door in a password manager. The consultant’s account went the same afternoon, and the Covenant DPA review picked up the question of what a consultant’s admin account had been covered by. That left one administrator, the Head of IT, on a dedicated admin account with no mailbox and a hardware key, which was the one arrangement on the board that had been done properly all along.
Then the break-glass account, which the privileged access page describes and the Home did not have: credentials in a sealed envelope in the Director’s safe, a second copy elsewhere, excluded from every policy, alerted on any sign-in, tested quarterly. It exists now, and it has been opened once, on purpose, to check that it works.
What an identity provider is for¶
The tenant page split one landlord into four. Four landlords means four logins per member of staff, unless one thing in front of them says who somebody is and the four believe it. That thing is the identity provider. If the mail provider is also the identity provider, losing the mail loses the logins to the files and the chat as well, the tenant again under a different name. So the identity provider is software from a fifth company, run by the Home, speaking OpenID Connect and SAML, and replaceable by exporting its configuration. Of the four, the file store takes it, and the mail and the chat keep their own doors. Its hostname is under the Home’s second name, so the public name can be taken without the logins going with it.
Three of the Home’s systems stay outside it, two because they cannot be brought in and one because the price of bringing it in lost two budget cycles. Bestiary runs on a server in the comms room and cannot federate to anything, so its forty-seven accounts stay local. The nine suspended ones were deleted. Covenant’s own login stays, with MFA switched from optional to required, which moved Kevin from the sixty per cent into the forty. The Great Ledger’s accounts belong to the Consortium, and the three former-staff ones were reported to it. The Home’s authority goes no further.
Three makers¶
The software choice came down to three, all European in their operation and one of them not in its origin.
Keycloak is an incubation project of the Cloud Native Computing Foundation, part of the Linux Foundation, with the trademark held by Red Hat. The code is open and runs anywhere, and the project’s home is a US foundation. Cloud-IAM, Cloud-IAM SAS of Rennes, runs it as a managed service since 2019, and its sub-processor list says a customer’s deployment lands on Outscale or Scaleway in Europe, or on Google, Amazon or Microsoft if the customer asks for those.
ZITADEL is CAOS AG of St. Gallen, under Swiss law with St. Gallen as the place of jurisdiction, offering identity and access management as a service under its own name. The software is open source under the AGPL and runs self-hosted on a Linux box, in Docker or on Kubernetes, so a customer who leaves the service keeps the product. Its trust centre names what the service runs on: Google Cloud Platform as the cloud provider for ZITADEL Cloud, in a region the customer designates, with Postmark for transactional mail and Twilio for SMS, both in the USA, unless the customer configures its own SMTP server and message gateway. A Swiss company on an American cloud.
Nubus is Univention GmbH of Bremen, the identity component inside openDesk, with a central portal, OpenID Connect and SAML, and integration with an existing Keycloak or Active Directory.
The Home went to ZITADEL, and took it home. ZITADEL Cloud would have put Google under the Home’s logins, the tenant page again with a Swiss letterhead, so the Home runs the AGPL version itself, on a virtual machine at Hetzner in Falkenstein beside the file store, with outgoing mail through the Home’s own mail provider and no SMS at all. That puts a Swiss product on a German machine in front of a German file store, with the Head of IT underneath it as the price. Cloud-IAM was the runner-up, and the reason it was second is the one written beside it: a French operator on a French cloud, running software whose project home is a US foundation, the way Sphinx and PyPI are written down on the Purple Lantern pages.
Keeper of keys¶
An identity provider that recovers through a mailbox it protects is a loop, the same one the Purple Lantern email page draws for the registrar. So the instance’s administrator account recovers through a mailbox at a provider that shares nothing with the four landlords, on a domain that is not the Home’s, and through the Head of IT’s hardware key, with recovery codes in the Home’s password vault. Each of the four landlords keeps one local administrator account of its own, with its own second factor, so that the identity provider going away locks staff out of the front door and not the administrators out of the building.
Volunteers got time-limited accounts that expire unless the volunteer coordinator renews them, which the offboarding page calls the sustainable version of a quarterly review. Everybody, staff and volunteer, got a second factor, and the policy that requires it lives in the identity provider, where a “skip for now” prompt cannot be clicked one time too many.
The key board¶
recovery: a mailbox at a fifth place, a hardware key, codes in the vault
│
identity provider (ZITADEL, self-hosted at Hetzner)
│
files, and the Burrow inside them
│
local admin
on their own second factors, a local admin each: mail (mailbox.org), chat (Threema Work)
outside it, on their own locks: Bestiary (comms room), Covenant (MFA required), the Great Ledger (Consortium)
in the Director's safe: the break-glass envelope
What could go wrong?
Hetzner suspends the account, or the virtual machine dies, and the staff are locked out of the files and the roster at once, while the local administrator is not.
The Head of IT, who is now the identity provider’s operator, is on holiday when the machine needs patching.
The Head of IT loses the hardware key on a Tuesday, and the break-glass envelope is what Wednesday looks like.
The former administrator’s password turns up in a leak, and finds an account that has been disabled for a year.
Kevin sets the same password on Covenant and Bestiary again, and one of the two is still outside the second factor.
The identity provider is gone, what now? Staff cannot log in to the files or the roster until it is back or replaced, and the mail and the chat keep working on their own doors. The local administrator account still opens the store. The nightly backup is restored on a fresh machine at another European host, or for a week on ZITADEL Cloud in a European region with Google underneath, the file store is pointed at it, and staff log in again, with the same second factors, because those were theirs and not the provider’s. Bestiary, Covenant and the Ledger never noticed.
Nanny Ogg’s front door key hangs on a nail beside the door, on the outside. In forty years nobody who was not an Ogg has dared to use it.