enTrail

Platform

How the platform works Beta

The platform console holds one identity for your organisation: the people, their second factors, and which boxes each may reach. A box holds none of that. It trusts a signed ticket and a signed list, and that difference is the whole design.

The beta console is live at demoplatform.entrail.io. Registration is open: create an organisation, add people, and try the sign-in described below. It is a beta environment, not production — it is for trying the system, so do not put anything in it you would need to rely on later. Evidence that has to stand up belongs on a box of your own.

Status. Registration and sign-in to the platform work today, in beta. The schema, the sign-in mechanism and the threat model are settled and under test, and the remaining screens are being built. This page describes the mechanism as specified; where something is not switched on yet it says so.

Why a box holds no passwords

A box is a machine that may sit in your data centre, may be offline for a week, and may be one of many. If each one kept its own passwords, then revoking a person would mean reaching every box, and a stolen box would mean stolen credentials. So boxes keep no passwords and no password resets.

Instead the platform issues two things, both signed, and a box verifies them without asking anyone:

Signing in, step by step

Signing in to a box through the platformThe browser opens the box, which redirects to the platform with a nonce. The platform authenticates the person, checks they are a custodian in the current manifest, and issues a signed five-minute ticket. The box verifies the ticket against the platform key and the manifest it holds, then starts its own session.BrowserYour boxThe platform1 open /login2 redirect: sign-in?box=…&nonce=N3 org id · username · passwordplus a code, if two-factor is on4 check: is this user a custodian, in the current manifest?5 ticket — signed, 5 min, single usedelivered by POST form, never in a URL6 POST /auth with the ticket7 verify: signature · box name · nonce · expiry · manifest8 session cookie, 8 henTraildocs.entrail.io
The box never sees a password and stores none. It trusts one signed ticket and the signed custodian list it pulls from the platform, and it seals its own record of the sign-in.

What the box checks before it lets anyone in

Only then does the box start its own session, and it seals a console.signin event into its own trail. Your sign-ins are evidence too.

The manifest, and what happens when we are unreachable

A box fetches the manifest about once a minute. It accepts one only if the version is higher than the one it holds and the issue time is not in the future, then keeps it on disk. If the platform is unreachable the box keeps working from the last manifest it verified and shows how old it is. A change to the list seals acustodian.granted, custodian.changed or custodian.revoked event on the box.

The honest consequence: revoking someone takes effect on a box within about a minute, not instantly, and a box that cannot reach us keeps honouring the last list it saw.

The platform keeps its own trail

Every change to people, roles and boxes is recorded as a config event, hash-chained to the one before it. The platform is held to the same standard as the product: you can ask what changed, when, and who did it, and the answer is not editable after the fact.

Read next