Identity & Access
OIDC, SAML, MFA, passkeys, LDAP and policy engines for explainable authentication and authorisation.
- OIDC
- SAML
- WebAuthn
- LDAP
Independent Engineering · Alsfeld, Germany
I design secure identity, mail and platform services — from architecture and code to dependable operations.
public service checksExpertise
It emerges from protocols, identities, data flows and operations that make deviations visible.
OIDC, SAML, MFA, passkeys, LDAP and policy engines for explainable authentication and authorisation.
Mail infrastructure built on Postfix, Dovecot and Rspamd, secured with DKIM, DANE, MTA-STS and TLSRPT.
Container and Kubernetes platforms whose rollouts, dependencies and failure states remain verifiable.
Metrics, logs and traces as part of the architecture — for sound conclusions instead of assumptions.
Selected open-source projects
Each project combines protocol fidelity, secure defaults and a clear path into production.
An identity and authentication platform written in Go, with OIDC, SAML, MFA, LDAP, Lua and mail integrations.
Safe DKIM key management across LDAP and DNS, with controlled generations and an automatable lifecycle.
An IMAP and POP3 proxy in Go that cleanly separates authentication from backend routing.
A lightweight PowerDNS interface with draft mode, pre-change review, optional OIDC and role-based access.
A Go policy server that evaluates sender IP addresses by country and frequency, blocking senders when countries change unexpectedly or too many distinct IPs appear.
A focused Postfix-to-HTTP wrapper that hands mail events to HTTP services in a controlled way.
Approach
Configuration, source and runtime are examined together. The visible symptom is rarely the complete cause.
Fail-closed behaviour, clear ownership and verifiable transitions are design properties.
Tests, metrics, traces and readbacks show whether a change really works where it is supposed to.
Monitoring, rollback and understandable runbooks belong to the solution, not to a later backlog.
Perspectives
Trust emerges from protocols, key material, policies and observable decisions — never from the interface alone.
Transport encryption, DNS trust, key lifecycles and deliverability have to work as one connected chain.
Image identity, restarts, endpoints, metrics and relevant failure paths determine whether the new state is dependable.
About
Computer scientist, open-source developer and independent system engineer, particularly interested in the difficult boundaries between protocols, software and operations.
Since 2002, I have worked with companies and public-sector organisations on demanding infrastructure and software projects. I focus on the areas where standard recipes fall short: distributed failures, security-critical identities, mail protocols and systems that must remain explainable under real production conditions.
Contact
Send me a short note with the context, your goal and the point where the system is currently not dependable enough.