Field report 10 · Identity and security
Signing in without passwords, for machines too
How static passwords disappear from the mail infrastructure, including for automations such as the ERP system.
- Status
- In trial Design in trial, not yet in production.
- Published
- Publisher
- SIMO GmbH, Aschaffenburg, Germany
Starting questionHow do we get rid of static passwords in the mail infrastructure, including for automations such as the ERP system?
What we trialled
People sign in through the browser with a passkey or a second factor. Every automation gets its own machine identity: a rotating client certificate or a short-lived token. That identity is bound to sender and source.
Modified third-party code is maintained as a separate fork instead of being changed inside the running container. The design is in trial.
What it means for business architecture
Machine identities are part of the identity architecture, not an operational detail. In the end a client secret is just a password under another name. Only a critical review of the design made that visible.
Learnings
- A design review finds the weak spots before they go live.
- A source address alone is no identity when several services share it.
- Changes made directly inside a container cannot be reproduced and are lost at the next rebuild.
- Third-party code under the AGPL comes with licence obligations. They belong in the plan from day one.
- passkey
- machine identity
- identity architecture