{% extends "base.html" %} {% block content %}

Access control

Authentication

Select the first factor for your organization. Every account also uses its PKIMaster authenticator.

Create external accounts in Users before switching providers. Roles are assigned here; provider email addresses and group claims never grant access. Saving revokes all sessions.

Sign-in policy

This fallback applies only to local administrators and still requires their authenticator. Local operators and auditors cannot use it.

OpenID Connect

Register an HTTPS callback ending in /auth/oidc/callback. The provider must support authorization code, PKCE S256, client_secret_basic, and RSA, RSA-PSS, or ECDSA signed ID tokens. Its TLS chain must be trusted by the host. OIDC sign-in returns to the exact configured callback.

OIDC accepts RSA provider keys from 2048 bits for interoperability and NIST P-256, P-384, or P-521 ECDSA keys. This provider policy is separate from the local CA's 3072-bit RSA minimum and is not a BSI compliance claim.

LDAP directory

LDAPS and mandatory StartTLS are supported. Certificate and hostname verification are required; LDAP referrals are disabled. User lookup must return exactly one entry whose DN matches the provisioned identity. Provider passwords are encrypted in the database.

{% endblock %}