Introducing Lemur
techblog.netflix.com
techblog.netflix.com
Yes. And hopefully that would be an impetus to move were that to happen. Any repo at one location that was at SF the day prior, and I knew they moves, immediately looks better in my eyes, because they are no longer helping support that system.
Dumb question: I'm an engineer who doesn't understand certificates outside of the basics of SSL. What are some cool things a small engineering team could do with Lemur (or certs in general)?
[1] https://www.digitalocean.com/community/tutorials/how-to-crea...
[2] http://nategood.com/client-side-certificate-authentication-i...
AD setups are actually pretty complete if you ask me. Heck, OpenLDAP is a lot to setup vs AD. Same for cert management. User management. Machine management. Kerberos that works (since most don't even understand it: its a ticketing authentication system - the thing we keep recreating and calling it something else).
It goes a long way - and I'm glad more tools are coming to narrow these gaps!
If you have the OpenSSL utility, you can generate the certificates right on the box where you're going to use the cert, and only have to move around the public portions of the key. It seems like it would be fairly trivial for Lemur to do with just a SSH shell, or an agent.
Someone care to edumacate me?
*: There are small teams with expert in x509. Most don't have such a luxury. For them to get certs right is near impossible.