novolis-security / getting-started.md
Getting started
Passwords, encryption, breach checks
dotnetsecuritynovolis
Password hashing (Argon2id), AES-256-GCM encryption, HaveIBeenPwned helpers, plus an access-token mint (Novolis.Security.OAuth), an outbound Novolis-issuer caller (Novolis.Security.OAuth.Client), and a tenant authorization framework (Novolis.Security.Authorization).
This is not a full Identity Provider and not a substitute for Duende IdentityServer, Keycloak, or Entra. Read what-this-is.md first.
Published guide: https://novolis-platform.github.io/.github/novolis-security/
Prerequisites
- .NET 10 SDK
- GitHub Packages auth for
Novolis.*(see nuget-only-policy)
Configure GPR once from a sibling novolis-governance checkout:
pwsh -File d:\novolis\novolis-governance\scripts\configure-gpr-user-nuget.ps1Install
dotnet add package Novolis.Security.EncryptionLocal multi-repo iteration uses ProjectReference mode via d:\novolis\Novolis.Platform.slnx — never a local NuGet folder feed.
Next
- what-this-is.md — token mint + tenant authz; not an IdP
- REFACTORING_SPEC.md — Authentication, OAuth, and Authorization end-state
- design.md — layer placement and non-goals
- owasp-security-evaluation.md — OWASP ASVS 5.0.0 evaluation of identity, hashing, and crypto libraries
- release.md — publish cadence
- Org docs catalog