3 ms·
Not sure why it would be so hard. All you need is a centralized authentication server (preferably including access logging) and a simple way to use it for all
by devit 5y ago
Not sure why it would be so hard.
All you need is a centralized authentication server (preferably including access logging) and a simple way to use it for all applications (the simplest is to have the app listen on localhost and expose it via nginx configured to use the authentication service).
I guess for real security you also need to forbid logins from non-secure devices, which is trivial if you can trust employees and only hire security-competent engineers, and otherwise needs dedicated devices, secure boot and remote attestation (which is also easy but will take some work to do).