Servers
Cloud Servers Cloud VPS Dedicated VPS Managed Cloud Servers Managed Cloud Dedicated Servers GPU Dedicated Servers Forex VPS
Hosting
cPanel Hosting WordPress Hosting WooCommerce Hosting cPanel Dedicated cPanel Reseller Nextcloud Hosting Sovereign Workspaces
Platform & Containers
Platform as a Service Red Hat OpenShift Docker Hosting Kubernetes n8n Hosting Dokploy Hosting Coolify Hosting Magento in PaaS WordPress in PaaS
Private Cloud
Virtual Private Cloud Dedicated Private Cloud HA Private Cloud White-Label Cloud Platform Colocation
Solutions
eCommerce Hosting Fintech Hosting Gaming Hosting Disaster Recovery Digital & Data Sovereignty VMware Replacement Sovereign Government Suite National Digital Identity For Developers For Enterprises AI Infrastructure Blockchain Hosting
Cyber Security
Security Overview DDoS Protection SSL Certificates HSM Decanus Terminal Backup Services Domains SOC Services Aramco CCC SABIC CyberTrust SAMA CSF NCA CCC NCA CSCC CITC CRF Saudi PDPL Qatar Cybersecurity UAE Cybersecurity GCC Cybersecurity CMMC NIS2 DORA TISAX
Support
Support Plans DevOps Support Nextcloud Support Proxmox Support VMware Replacement NOC Services
Resources
Technology Data Centers Network High Availability Storage Blog About Us Compare Contact
Browse All Industries →
Login Get Started
Keycloak + Nextcloud + LibreSign Three assurance levels MOSIP and PKI optional

National Digital Identity,
Built on Open Source

A usable, verified digital identity for every citizen and business, included in the base of the Sovereign Digital Government Suite. Keycloak provides the accounts and single sign-on, Nextcloud provides the enrolment workflow and the national register, and a state-controlled PKI provides legally strong signatures. Where a country has no eID or certificate authority, MassiveGRID adds MOSIP and a national PKI module on the same platform.

3
Assurance Levels
1
Login for All Services
$0
Per-Citizen Licence
HSM
Keys in State Hardware

Every Service Depends on Knowing Who Is Asking

In countries with an existing national eID, Keycloak federates with it and nothing else is added. In countries without one, MassiveGRID provides the national digital identity on the same platform. The software is already in the base; what must be added is the process of proving who someone is before an account is trusted, and that process is a Case pattern in Nextcloud: a form or a counter visit, a clerk's approval, an entry in the national register.

Every ministry service simply states which assurance level it requires. Businesses are handled the same way: a company account in Keycloak with authorised representatives who are Level 2 or 3 individuals, so a director signs for the company with her own certificate.

From Self-Registered to Qualified Signature

LevelHow the citizen gets itWhere it is recordedWhat it unlocks
Level 1: Self-registeredCreates an account in Keycloak with phone and email, verified by one-time codesKeycloak account, assurance level 1Consultations, information requests, appointment booking, complaints, newsletters
Level 2: VerifiedSubmits a Nextcloud Form with ID document and selfie, or joins a short Talk video check, or visits a municipal counter where a clerk checks the document. A clerk approves the caseKeycloak assurance raised to 2; citizen written into the national citizen register (Nextcloud Tables) with a unique identifierPermits, licences, grants, tax filing, benefits, school and health services, most business filings
Level 3: CertificateReceives a personal digital certificate from the national PKI (existing, or the optional module), held in the state HSM for remote signing from a phone, or on a smartcard, after Level 2 verificationCertificate bound to the Keycloak account and register entryProperty transfers, company registration, contracts with the state, court filings, any act requiring a qualified signature

What a Country with No eID Gets

A Verified Identity for Every Citizen

Usable within months, enrolled online or at any municipal counter, with MFA and a full audit trail.

A Clean National Citizen Register

Held in Nextcloud Tables, owned by the state, queryable by every ministry through one API.

Legally Strong Signatures

Through LibreSign, using the national PKI where one exists or the optional PKI module, for citizens, businesses and civil servants alike.

One Login for National and Municipal Services

Nextcloud, the mail platform, cPanel and WordPress all authenticate through Keycloak, so a citizen or officer has one account everywhere.

No Per-Citizen Licence Cost

Coverage of the whole population is a matter of hardware and enrolment staff, not permission from a vendor.

Company Accounts

A company account in Keycloak with authorised representatives who are Level 2 or 3 individuals, so banks, registries and ministries verify a business and the person acting for it in one step.

MOSIP as the Foundational ID System

For countries with no civil registry to anchor to, or with benefit programmes where duplicate identities cause real leakage.

The tiered approach does not do biometric deduplication at national scale, meaning the guarantee that one person cannot hold two identities under different names. Where that guarantee matters, that is the moment to add MOSIP. MOSIP is open source (MPL), designed for national scale, and in production in several countries. Because it plugs into Keycloak, it can be added in year two without disrupting services launched in year one on the base identity.

AspectBase identity (Keycloak + PKI + Nextcloud)With MOSIP added
EnrolmentDocument check by clerk, online or at counterBiometric capture (fingerprint, iris, face) at enrolment stations
UniquenessDocument and register checksBiometric deduplication across the whole population
IdentifierUnique number issued by the registerUnique national ID number issued by MOSIP
AuthenticationKeycloak (password, OTP, certificate)MOSIP eSignet (OIDC) federated into Keycloak; citizens still see the same login
CredentialsDigital certificate on phone or cardAdds physical ID card and verifiable digital credentials
Change to the rest of the stackNoneNone. Nextcloud, mail, websites and every ministry service keep working unchanged
Typical fitCountries with a civil registry, or wanting fast coverage firstCountries building a foundational ID from scratch, or with high leakage in benefit programmes

A National PKI for Level 3 Certificates

Many countries already operate a national PKI through a ministry, the central bank or a licensed trust service provider. Where it exists, LibreSign and Keycloak simply use it. Where it does not, MassiveGRID offers a PKI module built from three components.

01
Certificate authority

EJBCA (Keyfactor, LGPL community edition)

An offline national root, subordinate CAs per purpose (citizens, staff, servers, timestamps), registration authority workflows, OCSP and CRL, and standard enrolment protocols. The reference open-source CA: it already runs national and government CAs in several countries, works with hardware security modules, and provides the CA hierarchy that auditors and foreign trust lists expect.

02
Timestamping and remote signing

SignServer (same vendor, open source)

A timestamping authority so signatures stay valid after certificates expire, and a remote signing service so a citizen key lives in the state HSM and is used from a phone with MFA. Remote signing removes the need for smartcard readers, which is how most modern national signature schemes work; cards remain possible for those who want them.

03
Key protection

Hardware Security Module

Holds root and signing keys in certified hardware (Thales Luna, Utimaco, Entrust nShield); SoftHSM for development only. Required for any trust service that expects to be recognised by courts, banks or other governments. MassiveGRID already operates FIPS 140-2 validated HSMs for private cloud customers and applies the same key-ceremony and custody procedures here.

How it connects

  • Keycloak issues the certificate request after Level 2 verification; the EJBCA registration authority approves it against the citizen register
  • LibreSign applies signatures and validates chains against the EJBCA OCSP responder
  • The same CA issues staff certificates for certificate-based login to Keycloak and S/MIME in the mail platform
  • The national root is published so foreign governments and banks can validate certificates
  • Alignment with eIDAS-style requirements is a policy and audit exercise on top of the same software

Why not something simpler

LibreSign has a built-in CA option, which is adequate for internal sign-off but not for a national trust anchor.

Simpler alternatives such as Step-CA are excellent for internal staff and machine certificates but thin on registration workflows, CA hierarchy management and the compliance features a national CA is audited on, so they are not proposed for the national role.

Identity Enrolment Is a Case Pattern

The same Nextcloud workflow that handles a permit or a grant handles the verification of a person, so municipal counters run it from the first quarter.

1
Apply

The citizen submits a Nextcloud Form with an ID document and selfie, joins a short Talk video check, or visits a municipal counter where a clerk fills the same form on their behalf. A Level 1 account already exists from phone and email verification.

2
Review

Flow routes the case to a verification officer with a deadline. The officer checks the document against the register for duplicates and, where MOSIP is deployed, against biometric deduplication.

3
Approve

Approval raises the Keycloak assurance level to 2 and writes the citizen into the national register in Tables with a unique identifier. The applicant is notified by mail and sees the status in their account.

4
Certify (optional)

For Level 3, Keycloak issues a certificate request, the EJBCA registration authority approves it against the register, and the key is generated in the state HSM for remote signing from the citizen's phone, or written to a smartcard.

Data, Code and Keys Stay In-Country

The identity platform runs on the same in-country Proxmox and Ceph base as the rest of the suite, on government infrastructure or in a MassiveGRID sovereign facility, with ISO 27001 certified operations and 24/7 SOC monitoring. Root and signing keys never leave the state's HSM.

  • Every component open source: Keycloak, Nextcloud, LibreSign, EJBCA, SignServer, MOSIP
  • Federates with an existing eID or PKI instead of replacing it
  • Added in year two without touching services launched in year one
  • Operated by MassiveGRID under SLA or handed over with training
  • Same platform serves staff SSO, see Keycloak centralised SSO and Nextcloud enterprise SSO

National Digital Identity Questions

No. The base identity in Keycloak, Nextcloud and a PKI gives verified accounts and signatures within months. MOSIP is added only where biometric uniqueness is required, typically for a foundational ID from scratch or for benefit programmes with high leakage, and it federates into Keycloak so nothing else changes.
No. LibreSign and Keycloak use the existing certificate authority for Level 3 certificates and signature validation. The EJBCA, SignServer and HSM module is only for countries that have no national PKI at all.
With remote signing. The citizen's private key is generated and held in the state HSM, and a signature is authorised from the citizen's phone with multi-factor authentication through Keycloak. SignServer applies the signature and a timestamp. Smartcards remain available for citizens and officials who want them.
The components are the ones used by qualified trust service providers in Europe, with a proper offline root, subordinate CAs, OCSP, timestamping and HSM-protected keys. Recognition under eIDAS or an equivalent national framework is a policy and audit exercise on top of the software: MassiveGRID prepares the CA hierarchy, key ceremonies and documentation that an auditor expects, and the state or its trust service provider seeks the accreditation.
Ministries and authorised services, through role-based views and an API in Nextcloud Tables, with every access logged. Banks, insurers and other private verifiers get a verification endpoint that confirms an identity without exposing the underlying record. The state owns the data and sets the access policy.
Level 1 self-registration opens in the first quarter with the platform and Keycloak. Level 2 enrolment at municipal counters and online follows in months 3 to 12, as the first of the five patterns built as a template. Level 3 certificates are issued in the same period to business representatives and professionals once the national PKI is connected or deployed.

Map Your Identity Landscape

A discovery workshop to confirm whether an eID, civil registry and national PKI exist, which assurance levels your services need, and what the first year delivers.

Federates with existing eIDs
Keys in state HSM
No per-citizen licence
Talk to the Government Team