Go to file
Marti Raudsepp cf805f530f Prevent unintended access to sensitive fields (passwords, private keys) (#876)
Make sure that fields specified in filter, sortBy, etc. are model fields
and may be accessed. This is fixes a potential security issue.

The filter() function allowed guessing the content of password hashes
one character at a time.

The sort() function allowed the user to call an arbitrary method of an
arbitrary model attribute, for example sortBy=id&sortDir=distinct would
produce an unexpected error.
2017-08-16 09:38:42 -07:00
docs Updating documentation (#849) 2017-07-05 20:17:19 -07:00
gulp adding url context path to html templates (#814) 2017-05-25 10:20:32 -07:00
lemur Prevent unintended access to sensitive fields (passwords, private keys) (#876) 2017-08-16 09:38:42 -07:00
trustores initial commit 2015-06-22 13:47:27 -07:00
.bowerrc Fixing the paths related to javascript dependecies 2015-08-14 10:05:30 -07:00
.coveragerc Removing tests folder from coverage report. (#788) 2017-05-11 19:42:53 -07:00
.gitattributes adding automatic versioning 2015-11-30 10:43:41 -08:00
.gitignore Closes #278 and #199, Starting transition to marshmallow (#299) 2016-05-05 12:52:08 -07:00
.jshintignore Pleasing the JSHint gods 2015-07-21 13:36:03 -07:00
.jshintrc Adding a visualization for authorities. (#338) 2016-05-30 21:52:34 -07:00
.pre-commit-config.yaml Adding the ability to specify a per-certificate rotation policy. (#851) 2017-07-12 16:46:11 -07:00
.travis.yml Fixing Bandit findings and adding travis Bandit job (#759) 2017-04-24 18:37:03 -07:00
AUTHORS Version bump and needed documentation. 2015-10-24 11:18:27 -07:00
CHANGELOG.rst Fixed typo (#870) 2017-08-09 08:40:22 -07:00
Dockerfile Add docker setup for running tests on a docker enabled dev environment. (#771) 2017-04-28 09:28:06 -07:00
LICENSE Improving documentation layout 2015-12-31 11:12:56 -08:00
MANIFEST.in adding automatic versioning 2015-11-30 10:43:41 -08:00
Makefile adding url context path to build, adding documentation on url contextpath (#737) 2017-03-28 15:21:13 -07:00
OSSMETADATA adding OSSMETADATA for NetflixOSS tracking 2015-12-11 15:57:28 -08:00
README.rst Updating readme with supported python verisions (#524) 2016-11-22 17:09:21 -08:00
bower.json Update bower.json (#722) 2017-03-13 12:28:08 -07:00
config-default.py initial commit 2015-06-22 13:47:27 -07:00
docker-compose.yml Add docker setup for running tests on a docker enabled dev environment. (#771) 2017-04-28 09:28:06 -07:00
gulpfile.js Pleasing the PEP8 gods 2015-07-21 13:06:13 -07:00
package.json adding url context path to build, adding documentation on url contextpath (#737) 2017-03-28 15:21:13 -07:00
setup.cfg Ensuring that acme and cryptography respect different key types (#554) 2016-12-02 10:54:18 -08:00
setup.py Upgrade dependency pem to ==17.1.0 (#872) 2017-08-10 15:08:11 -07:00
tox.ini Initial work on #74. (#514) 2016-11-21 09:19:14 -08:00

README.rst

Lemur
=====

.. image:: https://badges.gitter.im/Join%20Chat.svg
   :alt: Join the chat at https://gitter.im/Netflix/lemur
   :target: https://gitter.im/Netflix/lemur?utm_source=badge&utm_medium=badge&utm_campaign=pr-badge&utm_content=badge

.. image:: https://readthedocs.org/projects/lemur/badge/?version=latest
    :target: https://lemur.readthedocs.org
    :alt: Latest Docs

.. image:: https://img.shields.io/badge/NetflixOSS-active-brightgreen.svg

.. image:: https://travis-ci.org/Netflix/lemur.svg
    :target: https://travis-ci.org/Netflix/lemur


Lemur manages TLS certificate creation. While not able to issue certificates itself, Lemur acts as a broker between CAs
and environments providing a central portal for developers to issue TLS certificates with 'sane' defaults.

It works on CPython 3.5. We deploy on Ubuntu and develop on OS X.


Project resources
=================

- `Lemur Blog Post <http://techblog.netflix.com/2015/09/introducing-lemur.html>`_
- `Documentation <http://lemur.readthedocs.org/>`_
- `Source code <https://github.com/netflix/lemur>`_
- `Issue tracker <https://github.com/netflix/lemur/issues>`_
- `Docker <https://github.com/Netflix/lemur-docker>`_