Field report 10 · Identity and security

Signing in without passwords, for machines too

How static passwords disappear from the mail infrastructure, including for automations such as the ERP system.

Status
In trial Design in trial, not yet in production.
Published
Publisher
SIMO GmbH, Aschaffenburg, Germany

Starting questionHow do we get rid of static passwords in the mail infrastructure, including for automations such as the ERP system?

What we trialled

People sign in through the browser with a passkey or a second factor. Every automation gets its own machine identity: a rotating client certificate or a short-lived token. That identity is bound to sender and source.

Modified third-party code is maintained as a separate fork instead of being changed inside the running container. The design is in trial.

What it means for business architecture

Machine identities are part of the identity architecture, not an operational detail. In the end a client secret is just a password under another name. Only a critical review of the design made that visible.

Learnings

  1. A design review finds the weak spots before they go live.
  2. A source address alone is no identity when several services share it.
  3. Changes made directly inside a container cannot be reproduced and are lost at the next rebuild.
  4. Third-party code under the AGPL comes with licence obligations. They belong in the plan from day one.
  • passkey
  • machine identity
  • identity architecture
  • email

Matching consulting service

From the Lab into consulting.

What we trial in the Lab, SIMO GmbH puts into practice as consultants: Business Data Strategy & Architecture for AI, following the Zero Friction Data Flow principle. These services relate to this report:

45 minutes, free of charge, with the SIMO GmbH consultants. The form is on simo-online.com.

More reports on the same topic