Subject area
Security principles
The principles behind every CIAS process, in one place: refuse when in doubt, indistinguishable refusals, no defaults for permissions, and behavior during outages.
Topics in this subject area
- 1.Reject when in doubt
No default tenant, no default administrator role, required configuration without a default. Why an application would rather not start than start generously.
- 2.Rejections that reveal nothing
Unknown and suspended look the same, public endpoints always answer the same way, admin rejections are identical. Why this way nobody can probe for information.
- 3.When CIAS or Keycloak fails
What happens during an outage: the tenant gate answers from memory, registration and administration answer with 503, a failed provisioning stays repeatable.