National Digital Identity,
Built on Open Source
A usable, verified digital identity for every citizen and business, included in the base of the Sovereign Digital Government Suite. Keycloak provides the accounts and single sign-on, Nextcloud provides the enrolment workflow and the national register, and a state-controlled PKI provides legally strong signatures. Where a country has no eID or certificate authority, MassiveGRID adds MOSIP and a national PKI module on the same platform.
Every Service Depends on Knowing Who Is Asking
In countries with an existing national eID, Keycloak federates with it and nothing else is added. In countries without one, MassiveGRID provides the national digital identity on the same platform. The software is already in the base; what must be added is the process of proving who someone is before an account is trusted, and that process is a Case pattern in Nextcloud: a form or a counter visit, a clerk's approval, an entry in the national register.
Every ministry service simply states which assurance level it requires. Businesses are handled the same way: a company account in Keycloak with authorised representatives who are Level 2 or 3 individuals, so a director signs for the company with her own certificate.
From Self-Registered to Qualified Signature
| Level | How the citizen gets it | Where it is recorded | What it unlocks |
|---|---|---|---|
| Level 1: Self-registered | Creates an account in Keycloak with phone and email, verified by one-time codes | Keycloak account, assurance level 1 | Consultations, information requests, appointment booking, complaints, newsletters |
| Level 2: Verified | Submits a Nextcloud Form with ID document and selfie, or joins a short Talk video check, or visits a municipal counter where a clerk checks the document. A clerk approves the case | Keycloak assurance raised to 2; citizen written into the national citizen register (Nextcloud Tables) with a unique identifier | Permits, licences, grants, tax filing, benefits, school and health services, most business filings |
| Level 3: Certificate | Receives a personal digital certificate from the national PKI (existing, or the optional module), held in the state HSM for remote signing from a phone, or on a smartcard, after Level 2 verification | Certificate bound to the Keycloak account and register entry | Property transfers, company registration, contracts with the state, court filings, any act requiring a qualified signature |
What a Country with No eID Gets
A Verified Identity for Every Citizen
Usable within months, enrolled online or at any municipal counter, with MFA and a full audit trail.
A Clean National Citizen Register
Held in Nextcloud Tables, owned by the state, queryable by every ministry through one API.
Legally Strong Signatures
Through LibreSign, using the national PKI where one exists or the optional PKI module, for citizens, businesses and civil servants alike.
One Login for National and Municipal Services
Nextcloud, the mail platform, cPanel and WordPress all authenticate through Keycloak, so a citizen or officer has one account everywhere.
No Per-Citizen Licence Cost
Coverage of the whole population is a matter of hardware and enrolment staff, not permission from a vendor.
Company Accounts
A company account in Keycloak with authorised representatives who are Level 2 or 3 individuals, so banks, registries and ministries verify a business and the person acting for it in one step.
MOSIP as the Foundational ID System
For countries with no civil registry to anchor to, or with benefit programmes where duplicate identities cause real leakage.
The tiered approach does not do biometric deduplication at national scale, meaning the guarantee that one person cannot hold two identities under different names. Where that guarantee matters, that is the moment to add MOSIP. MOSIP is open source (MPL), designed for national scale, and in production in several countries. Because it plugs into Keycloak, it can be added in year two without disrupting services launched in year one on the base identity.
| Aspect | Base identity (Keycloak + PKI + Nextcloud) | With MOSIP added |
|---|---|---|
| Enrolment | Document check by clerk, online or at counter | Biometric capture (fingerprint, iris, face) at enrolment stations |
| Uniqueness | Document and register checks | Biometric deduplication across the whole population |
| Identifier | Unique number issued by the register | Unique national ID number issued by MOSIP |
| Authentication | Keycloak (password, OTP, certificate) | MOSIP eSignet (OIDC) federated into Keycloak; citizens still see the same login |
| Credentials | Digital certificate on phone or card | Adds physical ID card and verifiable digital credentials |
| Change to the rest of the stack | None | None. Nextcloud, mail, websites and every ministry service keep working unchanged |
| Typical fit | Countries with a civil registry, or wanting fast coverage first | Countries building a foundational ID from scratch, or with high leakage in benefit programmes |
A National PKI for Level 3 Certificates
Many countries already operate a national PKI through a ministry, the central bank or a licensed trust service provider. Where it exists, LibreSign and Keycloak simply use it. Where it does not, MassiveGRID offers a PKI module built from three components.
EJBCA (Keyfactor, LGPL community edition)
An offline national root, subordinate CAs per purpose (citizens, staff, servers, timestamps), registration authority workflows, OCSP and CRL, and standard enrolment protocols. The reference open-source CA: it already runs national and government CAs in several countries, works with hardware security modules, and provides the CA hierarchy that auditors and foreign trust lists expect.
SignServer (same vendor, open source)
A timestamping authority so signatures stay valid after certificates expire, and a remote signing service so a citizen key lives in the state HSM and is used from a phone with MFA. Remote signing removes the need for smartcard readers, which is how most modern national signature schemes work; cards remain possible for those who want them.
Hardware Security Module
Holds root and signing keys in certified hardware (Thales Luna, Utimaco, Entrust nShield); SoftHSM for development only. Required for any trust service that expects to be recognised by courts, banks or other governments. MassiveGRID already operates FIPS 140-2 validated HSMs for private cloud customers and applies the same key-ceremony and custody procedures here.
How it connects
- Keycloak issues the certificate request after Level 2 verification; the EJBCA registration authority approves it against the citizen register
- LibreSign applies signatures and validates chains against the EJBCA OCSP responder
- The same CA issues staff certificates for certificate-based login to Keycloak and S/MIME in the mail platform
- The national root is published so foreign governments and banks can validate certificates
- Alignment with eIDAS-style requirements is a policy and audit exercise on top of the same software
Why not something simpler
LibreSign has a built-in CA option, which is adequate for internal sign-off but not for a national trust anchor.
Simpler alternatives such as Step-CA are excellent for internal staff and machine certificates but thin on registration workflows, CA hierarchy management and the compliance features a national CA is audited on, so they are not proposed for the national role.
Identity Enrolment Is a Case Pattern
The same Nextcloud workflow that handles a permit or a grant handles the verification of a person, so municipal counters run it from the first quarter.
The citizen submits a Nextcloud Form with an ID document and selfie, joins a short Talk video check, or visits a municipal counter where a clerk fills the same form on their behalf. A Level 1 account already exists from phone and email verification.
Flow routes the case to a verification officer with a deadline. The officer checks the document against the register for duplicates and, where MOSIP is deployed, against biometric deduplication.
Approval raises the Keycloak assurance level to 2 and writes the citizen into the national register in Tables with a unique identifier. The applicant is notified by mail and sees the status in their account.
For Level 3, Keycloak issues a certificate request, the EJBCA registration authority approves it against the register, and the key is generated in the state HSM for remote signing from the citizen's phone, or written to a smartcard.
Data, Code and Keys Stay In-Country
The identity platform runs on the same in-country Proxmox and Ceph base as the rest of the suite, on government infrastructure or in a MassiveGRID sovereign facility, with ISO 27001 certified operations and 24/7 SOC monitoring. Root and signing keys never leave the state's HSM.
- Every component open source: Keycloak, Nextcloud, LibreSign, EJBCA, SignServer, MOSIP
- Federates with an existing eID or PKI instead of replacing it
- Added in year two without touching services launched in year one
- Operated by MassiveGRID under SLA or handed over with training
- Same platform serves staff SSO, see Keycloak centralised SSO and Nextcloud enterprise SSO
National Digital Identity Questions
Where to Go Next
Map Your Identity Landscape
A discovery workshop to confirm whether an eID, civil registry and national PKI exist, which assurance levels your services need, and what the first year delivers.