open-vault/website
Joel Thompson 2dc468f4d1 auth/aws: Make identity alias configurable (#5247)
* auth/aws: Make identity alias configurable

This is inspired by #4178, though not quite exactly what is requested
there. Rather than just use RoleSessionName as the Identity alias, the
full ARN is uses as the Alias. This mitigates against concerns that an
AWS role with an insufficiently secured trust policy could allow an
attacker to generate arbitrary RoleSessionNames in AssumeRole calls to
impersonate anybody in the Identity store that had an alias set up.
By using the full ARN, the owner of the identity store has to explicitly
trust specific AWS roles in specific AWS accounts to generate an
appropriate RoleSessionName to map back to an identity.

Fixes #4178

* Respond to PR feedback

* Remove CreateOperation

Response to PR feedback
2018-09-26 08:27:12 -07:00
..
data Update GCP docs (#4898) 2018-07-11 15:52:22 -04:00
scripts Remove people from community section (#3099) 2017-08-02 17:57:19 -04:00
source auth/aws: Make identity alias configurable (#5247) 2018-09-26 08:27:12 -07:00
config.rb Bump for release 2018-09-05 13:17:37 -04:00
Gemfile update ffi (#5395) 2018-09-25 11:26:58 -07:00
Gemfile.lock update ffi (#5395) 2018-09-25 11:26:58 -07:00
LICENSE.md Update license 2017-03-08 11:38:38 -08:00
Makefile switch from GA to segment tracking (#4109) 2018-04-12 21:35:38 -05:00
packer.json switch from GA to segment tracking (#4109) 2018-04-12 21:35:38 -05:00
README.md Fix website command 2017-03-08 09:47:16 -08:00
redirects.txt Move UI docs from enterprise to OSS (#4565) 2018-05-17 08:48:10 -07:00

Vault Website

This subdirectory contains the entire source for the Vault Website. This is a Middleman project, which builds a static site from these source files.

Contributions Welcome!

If you find a typo or you feel like you can improve the HTML, CSS, or JavaScript, we welcome contributions. Feel free to open issues or pull requests like any normal GitHub project, and we'll merge it in.

Running the Site Locally

Running the site locally is simple. Clone this repo and run make website.

Then open up http://localhost:4567. Note that some URLs you may need to append ".html" to make them work (in the navigation).