[Integration] Integrate POLYAS as the first external Voting provider #3

Open
opened 2026-08-04 13:49:43 +02:00 by zemion · 1 comment
Owner

Scope

Implement POLYAS behind voting.provider., initially as an explicit operator-assisted handoff and later through a contracted machine interface.

Implementable now

  • export a frozen ballot/electorate handoff with hashes and provenance;
  • retain provider project/product/profile references and operator evidence;
  • import bounded signed result/protocol artifacts and verify the frozen binding;
  • expose assisted/manual state honestly in administration and audit history;
  • prevent voter credentials and raw votes from crossing the provider boundary.

Vendor input required for unattended operation

  • contracted API/protocol and versioning policy;
  • sandbox and representative fixtures;
  • exact ballot/electorate/weight/replacement semantics;
  • idempotency, sealing, cancellation, retry, and outcome-unknown behavior;
  • signed result/archive formats;
  • current certificate, Security Target, maintenance evidence, and evaluated configuration;
  • DPA, location, retention, incident, recovery, and continuity terms.

The public product UI is not a production API. Browser automation and screen scraping are excluded.

Certification warning

BSI-DSZ-CC-0862-V2-2021 was valid through 2026-06-24. Do not enable external_certified from that historical certificate alone. See docs/POLYAS_PROVIDER_PROFILE.md.

## Scope Implement POLYAS behind voting.provider.<id>, initially as an explicit operator-assisted handoff and later through a contracted machine interface. ## Implementable now - export a frozen ballot/electorate handoff with hashes and provenance; - retain provider project/product/profile references and operator evidence; - import bounded signed result/protocol artifacts and verify the frozen binding; - expose assisted/manual state honestly in administration and audit history; - prevent voter credentials and raw votes from crossing the provider boundary. ## Vendor input required for unattended operation - contracted API/protocol and versioning policy; - sandbox and representative fixtures; - exact ballot/electorate/weight/replacement semantics; - idempotency, sealing, cancellation, retry, and outcome-unknown behavior; - signed result/archive formats; - current certificate, Security Target, maintenance evidence, and evaluated configuration; - DPA, location, retention, incident, recovery, and continuity terms. The public product UI is not a production API. Browser automation and screen scraping are excluded. ## Certification warning BSI-DSZ-CC-0862-V2-2021 was valid through 2026-06-24. Do not enable external_certified from that historical certificate alone. See docs/POLYAS_PROVIDER_PROFILE.md.
Author
Owner

The normalized source ideas and user-story orientation are now preserved in govoplan/docs/PRODUCT_INPUT_REGISTER.md. This issue remains the canonical live work item for the corresponding outcome.

The normalized source ideas and user-story orientation are now preserved in `govoplan/docs/PRODUCT_INPUT_REGISTER.md`. This issue remains the canonical live work item for the corresponding outcome. <!-- product-input-register-2026-08-06 -->
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: GovOPlaN/govoplan-voting#3