mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
Update test plan and add sshd flow
This commit is contained in:
+4
-4
@@ -10,15 +10,15 @@ ENV DEBUG=1 GOPATH=/root/go PATH=$PATH:/root/go/src/github.com/gravitational/tel
|
||||
RUN apt-get install -y htop vim screen; \
|
||||
mkdir -p /root/go/src/github.com/gravitational/teleport
|
||||
|
||||
# allows ansible testing
|
||||
RUN apt-get install -y ansible
|
||||
# allows ansible and ssh testing
|
||||
RUN apt-get install -y ansible ssh inetutils-syslogd
|
||||
|
||||
# installs gops
|
||||
RUN go get -u github.com/google/gops
|
||||
RUN mkdir /var/run/sshd
|
||||
|
||||
VOLUME ["/teleport", "/var/lib/teleport"]
|
||||
COPY .bashrc /root/.bashrc
|
||||
COPY .screenrc /root/.screenrc
|
||||
COPY ./sshd/start.sh /usr/bin/start-sshd.sh
|
||||
|
||||
# expose only proxy ports (SSH and HTTPS)
|
||||
EXPOSE 3023 3080
|
||||
|
||||
@@ -38,6 +38,11 @@ enter-one:
|
||||
enter-two:
|
||||
docker exec -ti two-auth /bin/bash
|
||||
|
||||
# `make enter-sshd` gives you shell inside sshd container
|
||||
.PHONY:enter-sshd
|
||||
enter-sshd:
|
||||
docker exec -ti one-sshd /bin/bash
|
||||
|
||||
# `make enter-two-proxy` gives you shell inside proxy server
|
||||
# of cluster "two"
|
||||
#
|
||||
@@ -52,6 +57,10 @@ enter-two-proxy:
|
||||
enter-two-node:
|
||||
docker exec -ti two-node /bin/bash
|
||||
|
||||
.PHONY: export-certs
|
||||
export-certs:
|
||||
docker exec -i one /bin/bash -c "tctl auth export --type=user | sed s/cert-authority\ // > /mnt/shared/certs/teleport.pub"
|
||||
|
||||
.PHONY: setup-tc
|
||||
setup-tc:
|
||||
docker exec -i two-auth /bin/bash -c "tctl -c /root/go/src/github.com/gravitational/teleport/docker/two-auth.yaml create -f /root/go/src/github.com/gravitational/teleport/docker/two-tc.yaml"
|
||||
|
||||
+9
-1
@@ -16,7 +16,7 @@ from `$GOPATH/github.com/gravitational/teleport` (repository base dir).
|
||||
Type:
|
||||
|
||||
```bash
|
||||
$ make
|
||||
$ make up
|
||||
```
|
||||
|
||||
This will start two Teleport clusters:
|
||||
@@ -32,6 +32,14 @@ Type:
|
||||
$ make stop
|
||||
```
|
||||
|
||||
### SSH
|
||||
|
||||
SSH container needs User CA authorities exported:
|
||||
|
||||
```bash
|
||||
$ make export-certs
|
||||
```
|
||||
|
||||
### Configuration
|
||||
|
||||
Look at the [Makefile](Makefile): the containers are started with their
|
||||
|
||||
@@ -17,6 +17,7 @@ services:
|
||||
volumes:
|
||||
- ./data/one:/var/lib/teleport
|
||||
- ../:/root/go/src/github.com/gravitational/teleport
|
||||
- certs:/mnt/shared/certs
|
||||
networks:
|
||||
teleport:
|
||||
ipv4_address: 172.10.1.1
|
||||
@@ -39,6 +40,23 @@ services:
|
||||
teleport:
|
||||
ipv4_address: 172.10.1.20
|
||||
|
||||
#
|
||||
# one-node is a single-node Teleport cluster called "one" (runs all 3 roles: proxy, auth and node)
|
||||
#
|
||||
one-sshd:
|
||||
image: teleport:latest
|
||||
container_name: one-sshd
|
||||
command: /usr/bin/start-sshd.sh
|
||||
env_file: env.file
|
||||
mem_limit: 300m
|
||||
volumes:
|
||||
- ./sshd/pam.d/ssh:/etc/pam.d/ssh
|
||||
- ./sshd/etc/ssh/sshd_config:/etc/ssh/sshd_config
|
||||
- certs:/mnt/shared/certs
|
||||
networks:
|
||||
teleport:
|
||||
ipv4_address: 172.10.1.21
|
||||
|
||||
#
|
||||
# one-proxy is a second xproxy of the first cluster
|
||||
#
|
||||
@@ -120,3 +138,7 @@ networks:
|
||||
- subnet: 172.10.1.0/16
|
||||
ip_range: 172.10.1.0/24
|
||||
gateway: 172.10.1.254
|
||||
|
||||
|
||||
volumes:
|
||||
certs:
|
||||
@@ -0,0 +1,93 @@
|
||||
# Package generated configuration file
|
||||
# See the sshd_config(5) manpage for details
|
||||
|
||||
# What ports, IPs and protocols we listen for
|
||||
Port 22
|
||||
# Use these options to restrict which interfaces/protocols sshd will bind to
|
||||
#ListenAddress ::
|
||||
#ListenAddress 0.0.0.0
|
||||
Protocol 2
|
||||
# HostKeys for protocol version 2
|
||||
HostKey /etc/ssh/ssh_host_rsa_key
|
||||
HostKey /etc/ssh/ssh_host_dsa_key
|
||||
HostKey /etc/ssh/ssh_host_ecdsa_key
|
||||
HostKey /etc/ssh/ssh_host_ed25519_key
|
||||
#Privilege Separation is turned on for security
|
||||
UsePrivilegeSeparation yes
|
||||
|
||||
# Lifetime and size of ephemeral version 1 server key
|
||||
KeyRegenerationInterval 3600
|
||||
ServerKeyBits 1024
|
||||
|
||||
# Logging
|
||||
SyslogFacility AUTH
|
||||
LogLevel DEBUG3
|
||||
|
||||
# Authentication:
|
||||
LoginGraceTime 120
|
||||
PermitRootLogin without-password
|
||||
StrictModes yes
|
||||
|
||||
RSAAuthentication yes
|
||||
PubkeyAuthentication yes
|
||||
#AuthorizedKeysFile %h/.ssh/authorized_keys
|
||||
|
||||
# Don't read the user's ~/.rhosts and ~/.shosts files
|
||||
IgnoreRhosts yes
|
||||
# For this to work you will also need host keys in /etc/ssh_known_hosts
|
||||
RhostsRSAAuthentication no
|
||||
# similar for protocol version 2
|
||||
HostbasedAuthentication no
|
||||
# Uncomment if you don't trust ~/.ssh/known_hosts for RhostsRSAAuthentication
|
||||
#IgnoreUserKnownHosts yes
|
||||
|
||||
# To enable empty passwords, change to yes (NOT RECOMMENDED)
|
||||
PermitEmptyPasswords no
|
||||
|
||||
# allowe users to login
|
||||
PermitRootLogin yes
|
||||
|
||||
# Change to yes to enable challenge-response passwords (beware issues with
|
||||
# some PAM modules and threads)
|
||||
ChallengeResponseAuthentication no
|
||||
|
||||
# Change to no to disable tunnelled clear text passwords
|
||||
#PasswordAuthentication yes
|
||||
|
||||
# Kerberos options
|
||||
#KerberosAuthentication no
|
||||
#KerberosGetAFSToken no
|
||||
#KerberosOrLocalPasswd yes
|
||||
#KerberosTicketCleanup yes
|
||||
|
||||
# GSSAPI options
|
||||
#GSSAPIAuthentication no
|
||||
#GSSAPICleanupCredentials yes
|
||||
|
||||
X11Forwarding yes
|
||||
X11DisplayOffset 10
|
||||
PrintMotd no
|
||||
PrintLastLog yes
|
||||
TCPKeepAlive yes
|
||||
#UseLogin no
|
||||
|
||||
#MaxStartups 10:30:60
|
||||
#Banner /etc/issue.net
|
||||
|
||||
# Allow client to pass locale environment variables
|
||||
AcceptEnv LANG LC_*
|
||||
|
||||
Subsystem sftp /usr/lib/openssh/sftp-server
|
||||
|
||||
# Set this to 'yes' to enable PAM authentication, account processing,
|
||||
# and session processing. If this is enabled, PAM authentication will
|
||||
# be allowed through the ChallengeResponseAuthentication and
|
||||
# PasswordAuthentication. Depending on your PAM configuration,
|
||||
# PAM authentication via ChallengeResponseAuthentication may bypass
|
||||
# the setting of "PermitRootLogin without-password".
|
||||
# If you just want the PAM account and session checks to run without
|
||||
# PAM authentication, then enable this but set PasswordAuthentication
|
||||
# and ChallengeResponseAuthentication to 'no'.
|
||||
UsePAM yes
|
||||
|
||||
TrustedUserCAKeys /mnt/shared/certs/teleport.pub
|
||||
@@ -0,0 +1,55 @@
|
||||
# PAM configuration for the Secure Shell service
|
||||
|
||||
# Standard Un*x authentication.
|
||||
@include common-auth
|
||||
|
||||
# Disallow non-root logins when /etc/nologin exists.
|
||||
account required pam_nologin.so
|
||||
|
||||
# Uncomment and edit /etc/security/access.conf if you need to set complex
|
||||
# access limits that are hard to express in sshd_config.
|
||||
# account required pam_access.so
|
||||
|
||||
# Standard Un*x authorization.
|
||||
@include common-account
|
||||
|
||||
# SELinux needs to be the first session rule. This ensures that any
|
||||
# lingering context has been cleared. Without this it is possible that a
|
||||
# module could execute code in the wrong domain.
|
||||
session [success=ok ignore=ignore module_unknown=ignore default=bad] pam_selinux.so close
|
||||
|
||||
# Set the loginuid process attribute.
|
||||
session optional pam_loginuid.so
|
||||
|
||||
# Create a new session keyring.
|
||||
session optional pam_keyinit.so force revoke
|
||||
|
||||
# Standard Un*x session setup and teardown.
|
||||
@include common-session
|
||||
|
||||
# Print the message of the day upon successful login.
|
||||
# This includes a dynamically generated part from /run/motd.dynamic
|
||||
# and a static (admin-editable) part from /etc/motd.
|
||||
session optional pam_motd.so motd=/run/motd.dynamic
|
||||
session optional pam_motd.so noupdate
|
||||
|
||||
# Print the status of the user's mailbox upon successful login.
|
||||
session optional pam_mail.so standard noenv # [1]
|
||||
|
||||
# Set up user limits from /etc/security/limits.conf.
|
||||
session required pam_limits.so
|
||||
|
||||
# Read environment variables from /etc/environment and
|
||||
# /etc/security/pam_env.conf.
|
||||
session required pam_env.so # [1]
|
||||
# In Debian 4.0 (etch), locale-related environment variables were moved to
|
||||
# /etc/default/locale, so read that as well.
|
||||
session required pam_env.so user_readenv=1 envfile=/etc/default/locale
|
||||
|
||||
# SELinux needs to intervene at login time to ensure that the process starts
|
||||
# in the proper default security context. Only sessions which are intended
|
||||
# to run in the user's context should be run after this.
|
||||
session [success=ok ignore=ignore module_unknown=ignore default=bad] pam_selinux.so open
|
||||
|
||||
# Standard Un*x password updating.
|
||||
@include common-password
|
||||
@@ -0,0 +1,7 @@
|
||||
#!/bin/bash
|
||||
|
||||
while [ 1 ]
|
||||
do
|
||||
tctl auth export --type=user | sed s/cert-authority\ // > /mnt/shared/certs/teleport.pub
|
||||
sleep 10
|
||||
done
|
||||
Executable
+4
@@ -0,0 +1,4 @@
|
||||
#!/bin/bash
|
||||
|
||||
syslogd&
|
||||
/usr/sbin/sshd -D
|
||||
+23
-6
@@ -7,8 +7,7 @@ as well as an upgrade of the previous version of Teleport.
|
||||
- [ ] Adding nodes to a cluster
|
||||
- [ ] Adding Nodes via Valid Static Token
|
||||
- [ ] Adding Nodes via Valid Short-lived Tokens
|
||||
- [ ] Adding Nodes via Invalid Static Token Fails
|
||||
- [ ] Adding Nodes via Invalid Short-lived Tokens Fails
|
||||
- [ ] Adding Nodes via Invalid Token Fails
|
||||
- [ ] Revoking Node Invitation
|
||||
|
||||
- [ ] Labels
|
||||
@@ -18,17 +17,22 @@ as well as an upgrade of the previous version of Teleport.
|
||||
- [ ] Trusted Clusters
|
||||
- [ ] Adding Trusted Cluster Valid Static Token
|
||||
- [ ] Adding Trusted Cluster Valid Short-lived Token
|
||||
- [ ] Adding Trusted Cluster Invalid Static Token
|
||||
- [ ] Adding Trusted Cluster Invalid Short-lived Token
|
||||
- [ ] Adding Trusted Cluster Invalid Token
|
||||
- [ ] Removing Trusted Cluster
|
||||
|
||||
- [ ] RBAC
|
||||
|
||||
Make sure that invalid and valid attempts are reflected in audit log.
|
||||
|
||||
- [ ] Successfully connect to node with correct role
|
||||
- [ ] Unsuccessfully connect to a role in an in-valid role
|
||||
- [ ] Unsuccessfully connect to a node in a role restricting access by label
|
||||
- [ ] Unsuccessfully connect to a node in a role restricting access by invalid SSH login
|
||||
- [ ] Allow/deny role option: SSH agent forwarding
|
||||
- [ ] Allow/deny role option: Port forwarding
|
||||
|
||||
- [ ] Users
|
||||
With every user combination, try to login and signup with invalid second factor, invalid password to see how the system reacts.
|
||||
|
||||
- [ ] Adding Users Password Only
|
||||
- [ ] Adding Users OTP
|
||||
- [ ] Adding Users U2F
|
||||
@@ -58,12 +62,15 @@ as well as an upgrade of the previous version of Teleport.
|
||||
- [ ] Failed login attempts are recorded
|
||||
- [ ] Interactive sessions have the correct Server ID
|
||||
- [ ] Server ID is the ID of the node in regular mode
|
||||
- [ ] Server ID is of the proxy for proxy mode
|
||||
- [ ] Server ID is randomly generated for proxy node
|
||||
- [ ] Exec commands are recorded
|
||||
- [ ] `scp` commands are recorded
|
||||
- [ ] Subsystem results are recorded
|
||||
|
||||
- [ ] Interact with a cluster using `tsh`
|
||||
|
||||
These commands should ideally be tested for recording and non-recording modes as they are implemented in a different ways.
|
||||
|
||||
- [ ] tsh ssh \<regular-node\>
|
||||
- [ ] tsh ssh \<node-remote-cluster\>
|
||||
- [ ] tsh ssh -A \<regular-node\>
|
||||
@@ -82,6 +89,7 @@ as well as an upgrade of the previous version of Teleport.
|
||||
- [ ] tsh clusters
|
||||
|
||||
- [ ] Interact with a cluster using `ssh`
|
||||
Make sure to test both recording and regular proxy modes.
|
||||
- [ ] ssh \<regular-node\>
|
||||
- [ ] ssh \<node-remote-cluster\>
|
||||
- [ ] ssh -A \<regular-node\>
|
||||
@@ -116,6 +124,14 @@ interactive sessions the 12 combinations are below.
|
||||
- [ ] Connect to a Teleport node in a remote cluster using Teleport.
|
||||
- [ ] Connect to a Teleport node in a remote cluster using the Web UI.
|
||||
|
||||
### Migrations
|
||||
|
||||
* [ ] Migrate trusted clusters from 2.4.0 to 2.5.0
|
||||
* [ ] Migrate auth server on main cluster, then rest of the servers on main cluster
|
||||
SSH should work for both main and old clusters
|
||||
* [ ] Migrate auth server on remote cluster, then rest of the remote cluster
|
||||
SSH should work
|
||||
|
||||
### Command Templates
|
||||
|
||||
When interacting with a cluster, the following command templates are useful:
|
||||
@@ -151,3 +167,4 @@ tsh --proxy=proxy.example.com --user=<username> --insecure ssh -A -p 22 node.exa
|
||||
# the --cluster flag is used to connect to a node in a remote cluster.
|
||||
tsh --proxy=proxy.example.com --user=<username> --insecure --cluster=foo.com ssh -p 22 node.foo.com
|
||||
```
|
||||
|
||||
|
||||
Reference in New Issue
Block a user