FOSS Evaluation and IAM/IdP
Who would be willing help evaluate software for members and/or use for internal purposes? We also need some standard practices, procedures, and tools for this purpose. There are lots of informative resources for using FOSS as components in other projects, which is not exactly right for Chattanooga.Digital since we primarily deploy off-the-shelf FOSS (although one aspect of this is how to evaluate custom or special purpose apps for members, which would be a fee-based service). The "grand-daddy" seems to be https://dwheeler.com/oss_fs_eval.html from 2011. The author includes lots of good resources although a few seem to be outdated. The Concise Guide for Evaluating Open Source Software <https://best.openssf.org/Concise-Guide-for-Evaluating-Open-Source-Software.h...> by the Open Source Security Foundation is really good. Another one I like is https://leaddev.com/software-quality/12-things-consider-when-assessing-open-... because it seems practical and thorough. Let's combine key elements from these to create a review protocol and scoresheet. At the same time, we need to look at identify and access management (IAM) software. I suggest we use this to hammer out the process, etc. The key missing element with the frameworks is "why." What is the purpose for and requirements of the software? A related element is the user, specifically the "sponsor" that requires the software. For IAM, the sponsor is us, the cooperative, including all members. The basic purpose, as the term implies, is to manage members' access to resources, including and via a digital identity. Our digital identities are a collection of attributes, credentials, data, and devices that represent us. As mentioned in a prior email, the fundamental purpose of Chattanooga.Digital is to give members complete control and full ownership of our digital assets, including our digital identities. More practically, we need: * Authentication via passkeys, passwords, and other factors for single sign-on to as many of our apps/systems as possible. * Authorization for access to apps, data, files, etc., with permissions in various roles. * Automation of user account management as needs for authentication and authorization change. * Governance and monitoring of access, including all of the above, for accounting, compliance, planning, and security purposes. * Via standard methods and protocols: OAuth, OIDC, SAML, etc. Beyond that, we need to position Chattanooga.Digital as a digital identity provider (IdP) for members to access other systems and own data about that access. The main things about this is (a) complementing/replacing centralized digital IDs (b) with a trusted source and (c) supporting decentralized self-sovereign IDs. See https://www.cloudflare.com/learning/access-management/what-is-an-identity-pr..., https://www.corbado.com/blog/digital-identity-guide, and https://www.imperva.com/learn/data-security/identity-providers-idps/ for background on this. Please chime in with your thoughts about evaluation approach, methods, process, etc., and how to apply all of that to IAM. Thanks! -- GL
On 8/27/26 3:50 PM, Greg Laudeman wrote:
Who would be willing help evaluate software for members and/or use for internal purposes? We also need some standard practices, procedures, and tools for this purpose.
FYI, here's a great article on these very topics: https://startwithidentity.com/articles/top-10-open-source-iam-solutions/ The site is a "vendor-neutral reference for the whole field: workforce IAM, CIAM, privileged access, identity governance, zero trust, and passwordless" so a good topical resource. Anyone interested in trying some of these out? -- Greg Laudeman, Ed.D., Instigator Chattanooga.Digital <https://chattanooga.digital/> greg@chattanooga.digital <mailto:greg.laudeman@chattanooga.digital> 706-271-5521
OK, so we have at least one victim... I mean *volunteer* 😁... for this. We had a good initial discussion on our weekly devops call. For those interested, when might be a good time to meet? My general sense is that "over lunch" or right "after work" are best, especially cuz I'm not a morning person. I created a meeting request via Nextcloud <https://cloud.chattanooga.digital/apps/calendar/proposal/1243152f20028df4853...>, which hopefully you got an email to select a good time, based on that. Let me know if you didn't and/or if there are other better times for such meetings. *_IMPORTANT NOTE: _/You must scroll/zoom the window to the lower right hand corner to find the "Submit" button./* It's partially obscured by the branding message (which we need to remove/replace). On 9/1/26 12:50 PM, Greg Laudeman wrote:
On 8/27/26 3:50 PM, Greg Laudeman wrote:
Who would be willing help evaluate software for members and/or use for internal purposes? We also need some standard practices, procedures, and tools for this purpose.
FYI, here's a great article on these very topics: https://startwithidentity.com/articles/top-10-open-source-iam-solutions/
The site is a "vendor-neutral reference for the whole field: workforce IAM, CIAM, privileged access, identity governance, zero trust, and passwordless" so a good topical resource.
Anyone interested in trying some of these out?
Hi Greg, I just went and completed this and it appears to have captured my responses as the advisors list user instead of my identity. I clicked the link in this email to perform the operation. Now that's an interesting bug, ironic as it shows the need for bullet-proof identity. Talk to you soon, thanks. Sent with [Proton Mail](https://proton.me/mail/home) secure email. On Wednesday, September 2nd, 2026 at 3:55 PM, Greg Laudeman via Advisors <advisors@list.chattanooga.digital> wrote:
OK, so we have at least one victim... I mean *volunteer* 😁... for this. We had a good initial discussion on our weekly devops call.
For those interested, when might be a good time to meet? My general sense is that "over lunch" or right "after work" are best, especially cuz I'm not a morning person.
I created a [meeting request via Nextcloud](https://cloud.chattanooga.digital/apps/calendar/proposal/1243152f20028df4853...), which hopefully you got an email to select a good time, based on that. Let me know if you didn't and/or if there are other better times for such meetings.
IMPORTANT NOTE: You must scroll/zoom the window to the lower right hand corner to find the "Submit" button. It's partially obscured by the branding message (which we need to remove/replace).
On 9/1/26 12:50 PM, Greg Laudeman wrote:
On 8/27/26 3:50 PM, Greg Laudeman wrote:
Who would be willing help evaluate software for members and/or use for internal purposes? We also need some standard practices, procedures, and tools for this purpose.
FYI, here's a great article on these very topics: https://startwithidentity.com/articles/top-10-open-source-iam-solutions/
The site is a "vendor-neutral reference for the whole field: workforce IAM, CIAM, privileged access, identity governance, zero trust, and passwordless" so a good topical resource.
Anyone interested in trying some of these out?
Yeah, that’s more of a side-effect for how meeting requests work in Next Cloud, it doesn’t care that I’m logged in – that link is still taking me to the advisory e-mail (and so everyone is just stepping on each other’s submissions). Those invite links have to be personalized per e-mail, you should have another invitee e-mail which should use your e-mail correctly. Thanks, William Roush | https://www.roushtech.net/ | 423.933.2114 Office: 423.933.2114 x1000 | Cell: 423.463.0592 | Email: william.roush@roushtech.net<mailto:william.roush@roushtech.net> Book a meeting: https://cal.roushtech.net/william.roush From: Rob Aitchison via Advisors <advisors@list.chattanooga.digital> Sent: Thursday, September 3, 2026 10:31 To: Greg Laudeman <greg.laudeman@chattanooga.digital> Cc: C.D Advisors <advisors@list.chattanooga.digital> Subject: [Advisors] Re: Meet about IAM evaluation Hi Greg, I just went and completed this and it appears to have captured my responses as the advisors list user instead of my identity. I clicked the link in this email to perform the operation. Now that's an interesting bug, ironic as it shows the need for bullet-proof identity. Talk to you soon, thanks. Sent with Proton Mail<https://proton.me/mail/home> secure email. On Wednesday, September 2nd, 2026 at 3:55 PM, Greg Laudeman via Advisors <advisors@list.chattanooga.digital<mailto:advisors@list.chattanooga.digital>> wrote: OK, so we have at least one victim... I mean *volunteer* 😁... for this. We had a good initial discussion on our weekly devops call. For those interested, when might be a good time to meet? My general sense is that "over lunch" or right "after work" are best, especially cuz I'm not a morning person. I created a meeting request via Nextcloud<https://cloud.chattanooga.digital/apps/calendar/proposal/1243152f20028df4853...>, which hopefully you got an email to select a good time, based on that. Let me know if you didn't and/or if there are other better times for such meetings. IMPORTANT NOTE: You must scroll/zoom the window to the lower right hand corner to find the "Submit" button. It's partially obscured by the branding message (which we need to remove/replace). On 9/1/26 12:50 PM, Greg Laudeman wrote: On 8/27/26 3:50 PM, Greg Laudeman wrote: Who would be willing help evaluate software for members and/or use for internal purposes? We also need some standard practices, procedures, and tools for this purpose. FYI, here's a great article on these very topics: https://startwithidentity.com/articles/top-10-open-source-iam-solutions/ The site is a "vendor-neutral reference for the whole field: workforce IAM, CIAM, privileged access, identity governance, zero trust, and passwordless" so a good topical resource. Anyone interested in trying some of these out?
Thanks Will, I figured that out as well. Only use the invite directed to your user, not the advisors list version of the link. :) Sent with [Proton Mail](https://proton.me/mail/home) secure email. On Thursday, September 3rd, 2026 at 10:38 AM, William Roush <william.roush@roushtech.net> wrote:
Yeah, that’s more of a side-effect for how meeting requests work in Next Cloud, it doesn’t care that I’m logged in – that link is still taking me to the advisory e-mail (and so everyone is just stepping on each other’s submissions).
Those invite links have to be personalized per e-mail, you should have another invitee e-mail which should use your e-mail correctly.
Thanks,
William Roush | https://www.roushtech.net/| 423.933.2114
Office: 423.933.2114 x1000 | Cell: 423.463.0592 | Email: william.roush@roushtech.net
Book a meeting: https://cal.roushtech.net/william.roush
From: Rob Aitchison via Advisors <advisors@list.chattanooga.digital> Sent: Thursday, September 3, 2026 10:31 To: Greg Laudeman <greg.laudeman@chattanooga.digital> Cc: C.D Advisors <advisors@list.chattanooga.digital> Subject: [Advisors] Re: Meet about IAM evaluation
Hi Greg,
I just went and completed this and it appears to have captured my responses as the advisors list user instead of my identity. I clicked the link in this email to perform the operation.
Now that's an interesting bug, ironic as it shows the need for bullet-proof identity.
Talk to you soon, thanks.
Sent with [Proton Mail](https://proton.me/mail/home) secure email.
On Wednesday, September 2nd, 2026 at 3:55 PM, Greg Laudeman via Advisors <advisors@list.chattanooga.digital> wrote:
OK, so we have at least one victim... I mean *volunteer* 😁... for this. We had a good initial discussion on our weekly devops call.
For those interested, when might be a good time to meet? My general sense is that "over lunch" or right "after work" are best, especially cuz I'm not a morning person.
I created a [meeting request via Nextcloud](https://cloud.chattanooga.digital/apps/calendar/proposal/1243152f20028df4853...), which hopefully you got an email to select a good time, based on that. Let me know if you didn't and/or if there are other better times for such meetings.
IMPORTANT NOTE: You must scroll/zoom the window to the lower right hand corner to find the "Submit" button. It's partially obscured by the branding message (which we need to remove/replace).
On 9/1/26 12:50 PM, Greg Laudeman wrote:
On 8/27/26 3:50 PM, Greg Laudeman wrote:
Who would be willing help evaluate software for members and/or use for internal purposes? We also need some standard practices, procedures, and tools for this purpose.
FYI, here's a great article on these very topics: https://startwithidentity.com/articles/top-10-open-source-iam-solutions/
The site is a "vendor-neutral reference for the whole field: workforce IAM, CIAM, privileged access, identity governance, zero trust, and passwordless" so a good topical resource.
Anyone interested in trying some of these out?
On 9/3/26 10:38 AM, William Roush wrote:
Yeah, that’s more of a side-effect for how meeting requests work in Next Cloud, it doesn’t care that I’m logged in – that link is still taking me to the advisory e-mail (and so everyone is just stepping on each other’s submissions).
Those invite links have to be personalized per e-mail, you should have another invitee e-mail which should use your e-mail correctly.
Sorry about that, folks! I should not have used the list email for selecting meeting days/times. Please respond using the link that came to you directly, not to advisors@list.chattanooga.digital. Live and learn. 😉 -- Greg Laudeman, Ed.D., Instigator Chattanooga.Digital <https://chattanooga.digital/> greg@chattanooga.digital <mailto:greg.laudeman@chattanooga.digital> 706-271-5521
Adam is out all next week traveling so I've revised the poll for the week of 9/14. You should have received another email asking for your response. I've still limited it to lunch/mid-day and after work/early evening. Let me know if other times might be better. Thanks! -- Greg Laudeman, Ed.D., Instigator Chattanooga.Digital <https://chattanooga.digital/> greg@chattanooga.digital <mailto:greg.laudeman@chattanooga.digital> 706-271-5521
participants (3)
-
Greg Laudeman -
Rob Aitchison -
William Roush