Post is very confusing.. If you are writing an enterprise app, you would be crazy not to build it to support windows active directory (which itself leverages Kerberos) for authentication. However, you start talking about letsencrypt/ SSL and it gets a bit sideways. Further, security is more than just authentication systems. It's typically thought of in terms of confidentiality, integrity, and availability, each of which have a lot of nuances (for example, integrity might represent audit logging, request tampering, journaling).