Since our user management is now done in HaSpMan, and the IdP is Keycloak, we no longer need OpenLDAP.
It should be possible to assign the right to use the "Door" to a user in HaSpMan, and still leverage the power of a local-only approach to open the door. This will still be the biggest challenge: creating a hybrid application, where HaSpMan is running on a cloud, on the public internet, while this service should still be working on the local network only.