diff --git a/docker/Dockerfile b/docker/Dockerfile index c051cea714c..ba4a9c1ab88 100644 --- a/docker/Dockerfile +++ b/docker/Dockerfile @@ -10,15 +10,15 @@ ENV DEBUG=1 GOPATH=/root/go PATH=$PATH:/root/go/src/github.com/gravitational/tel RUN apt-get install -y htop vim screen; \ mkdir -p /root/go/src/github.com/gravitational/teleport -# allows ansible testing -RUN apt-get install -y ansible +# allows ansible and ssh testing +RUN apt-get install -y ansible ssh inetutils-syslogd -# installs gops -RUN go get -u github.com/google/gops +RUN mkdir /var/run/sshd VOLUME ["/teleport", "/var/lib/teleport"] COPY .bashrc /root/.bashrc COPY .screenrc /root/.screenrc +COPY ./sshd/start.sh /usr/bin/start-sshd.sh # expose only proxy ports (SSH and HTTPS) EXPOSE 3023 3080 diff --git a/docker/Makefile b/docker/Makefile index fd7af313eda..573b8a1baa3 100644 --- a/docker/Makefile +++ b/docker/Makefile @@ -38,6 +38,11 @@ enter-one: enter-two: docker exec -ti two-auth /bin/bash +# `make enter-sshd` gives you shell inside sshd container +.PHONY:enter-sshd +enter-sshd: + docker exec -ti one-sshd /bin/bash + # `make enter-two-proxy` gives you shell inside proxy server # of cluster "two" # @@ -52,6 +57,10 @@ enter-two-proxy: enter-two-node: docker exec -ti two-node /bin/bash +.PHONY: export-certs +export-certs: + docker exec -i one /bin/bash -c "tctl auth export --type=user | sed s/cert-authority\ // > /mnt/shared/certs/teleport.pub" + .PHONY: setup-tc setup-tc: docker exec -i two-auth /bin/bash -c "tctl -c /root/go/src/github.com/gravitational/teleport/docker/two-auth.yaml create -f /root/go/src/github.com/gravitational/teleport/docker/two-tc.yaml" diff --git a/docker/README.md b/docker/README.md index 4db1a0b2717..46e89a4a898 100644 --- a/docker/README.md +++ b/docker/README.md @@ -16,7 +16,7 @@ from `$GOPATH/github.com/gravitational/teleport` (repository base dir). Type: ```bash -$ make +$ make up ``` This will start two Teleport clusters: @@ -32,6 +32,14 @@ Type: $ make stop ``` +### SSH + +SSH container needs User CA authorities exported: + +```bash +$ make export-certs +``` + ### Configuration Look at the [Makefile](Makefile): the containers are started with their diff --git a/docker/docker-compose.yml b/docker/docker-compose.yml index 061e3835977..2713566da9a 100644 --- a/docker/docker-compose.yml +++ b/docker/docker-compose.yml @@ -17,6 +17,7 @@ services: volumes: - ./data/one:/var/lib/teleport - ../:/root/go/src/github.com/gravitational/teleport + - certs:/mnt/shared/certs networks: teleport: ipv4_address: 172.10.1.1 @@ -39,6 +40,23 @@ services: teleport: ipv4_address: 172.10.1.20 + # + # one-node is a single-node Teleport cluster called "one" (runs all 3 roles: proxy, auth and node) + # + one-sshd: + image: teleport:latest + container_name: one-sshd + command: /usr/bin/start-sshd.sh + env_file: env.file + mem_limit: 300m + volumes: + - ./sshd/pam.d/ssh:/etc/pam.d/ssh + - ./sshd/etc/ssh/sshd_config:/etc/ssh/sshd_config + - certs:/mnt/shared/certs + networks: + teleport: + ipv4_address: 172.10.1.21 + # # one-proxy is a second xproxy of the first cluster # @@ -120,3 +138,7 @@ networks: - subnet: 172.10.1.0/16 ip_range: 172.10.1.0/24 gateway: 172.10.1.254 + + +volumes: + certs: \ No newline at end of file diff --git a/docker/sshd/etc/ssh/sshd_config b/docker/sshd/etc/ssh/sshd_config new file mode 100644 index 00000000000..c7b6aa23ecb --- /dev/null +++ b/docker/sshd/etc/ssh/sshd_config @@ -0,0 +1,93 @@ +# Package generated configuration file +# See the sshd_config(5) manpage for details + +# What ports, IPs and protocols we listen for +Port 22 +# Use these options to restrict which interfaces/protocols sshd will bind to +#ListenAddress :: +#ListenAddress 0.0.0.0 +Protocol 2 +# HostKeys for protocol version 2 +HostKey /etc/ssh/ssh_host_rsa_key +HostKey /etc/ssh/ssh_host_dsa_key +HostKey /etc/ssh/ssh_host_ecdsa_key +HostKey /etc/ssh/ssh_host_ed25519_key +#Privilege Separation is turned on for security +UsePrivilegeSeparation yes + +# Lifetime and size of ephemeral version 1 server key +KeyRegenerationInterval 3600 +ServerKeyBits 1024 + +# Logging +SyslogFacility AUTH +LogLevel DEBUG3 + +# Authentication: +LoginGraceTime 120 +PermitRootLogin without-password +StrictModes yes + +RSAAuthentication yes +PubkeyAuthentication yes +#AuthorizedKeysFile %h/.ssh/authorized_keys + +# Don't read the user's ~/.rhosts and ~/.shosts files +IgnoreRhosts yes +# For this to work you will also need host keys in /etc/ssh_known_hosts +RhostsRSAAuthentication no +# similar for protocol version 2 +HostbasedAuthentication no +# Uncomment if you don't trust ~/.ssh/known_hosts for RhostsRSAAuthentication +#IgnoreUserKnownHosts yes + +# To enable empty passwords, change to yes (NOT RECOMMENDED) +PermitEmptyPasswords no + +# allowe users to login +PermitRootLogin yes + +# Change to yes to enable challenge-response passwords (beware issues with +# some PAM modules and threads) +ChallengeResponseAuthentication no + +# Change to no to disable tunnelled clear text passwords +#PasswordAuthentication yes + +# Kerberos options +#KerberosAuthentication no +#KerberosGetAFSToken no +#KerberosOrLocalPasswd yes +#KerberosTicketCleanup yes + +# GSSAPI options +#GSSAPIAuthentication no +#GSSAPICleanupCredentials yes + +X11Forwarding yes +X11DisplayOffset 10 +PrintMotd no +PrintLastLog yes +TCPKeepAlive yes +#UseLogin no + +#MaxStartups 10:30:60 +#Banner /etc/issue.net + +# Allow client to pass locale environment variables +AcceptEnv LANG LC_* + +Subsystem sftp /usr/lib/openssh/sftp-server + +# Set this to 'yes' to enable PAM authentication, account processing, +# and session processing. If this is enabled, PAM authentication will +# be allowed through the ChallengeResponseAuthentication and +# PasswordAuthentication. Depending on your PAM configuration, +# PAM authentication via ChallengeResponseAuthentication may bypass +# the setting of "PermitRootLogin without-password". +# If you just want the PAM account and session checks to run without +# PAM authentication, then enable this but set PasswordAuthentication +# and ChallengeResponseAuthentication to 'no'. +UsePAM yes + +TrustedUserCAKeys /mnt/shared/certs/teleport.pub diff --git a/docker/sshd/pam.d/ssh b/docker/sshd/pam.d/ssh new file mode 100644 index 00000000000..955b02143d9 --- /dev/null +++ b/docker/sshd/pam.d/ssh @@ -0,0 +1,55 @@ +# PAM configuration for the Secure Shell service + +# Standard Un*x authentication. +@include common-auth + +# Disallow non-root logins when /etc/nologin exists. +account required pam_nologin.so + +# Uncomment and edit /etc/security/access.conf if you need to set complex +# access limits that are hard to express in sshd_config. +# account required pam_access.so + +# Standard Un*x authorization. +@include common-account + +# SELinux needs to be the first session rule. This ensures that any +# lingering context has been cleared. Without this it is possible that a +# module could execute code in the wrong domain. +session [success=ok ignore=ignore module_unknown=ignore default=bad] pam_selinux.so close + +# Set the loginuid process attribute. +session optional pam_loginuid.so + +# Create a new session keyring. +session optional pam_keyinit.so force revoke + +# Standard Un*x session setup and teardown. +@include common-session + +# Print the message of the day upon successful login. +# This includes a dynamically generated part from /run/motd.dynamic +# and a static (admin-editable) part from /etc/motd. +session optional pam_motd.so motd=/run/motd.dynamic +session optional pam_motd.so noupdate + +# Print the status of the user's mailbox upon successful login. +session optional pam_mail.so standard noenv # [1] + +# Set up user limits from /etc/security/limits.conf. +session required pam_limits.so + +# Read environment variables from /etc/environment and +# /etc/security/pam_env.conf. +session required pam_env.so # [1] +# In Debian 4.0 (etch), locale-related environment variables were moved to +# /etc/default/locale, so read that as well. +session required pam_env.so user_readenv=1 envfile=/etc/default/locale + +# SELinux needs to intervene at login time to ensure that the process starts +# in the proper default security context. Only sessions which are intended +# to run in the user's context should be run after this. +session [success=ok ignore=ignore module_unknown=ignore default=bad] pam_selinux.so open + +# Standard Un*x password updating. +@include common-password diff --git a/docker/sshd/scripts/export.sh b/docker/sshd/scripts/export.sh new file mode 100644 index 00000000000..238dfa3edf4 --- /dev/null +++ b/docker/sshd/scripts/export.sh @@ -0,0 +1,7 @@ +#!/bin/bash + +while [ 1 ] +do + tctl auth export --type=user | sed s/cert-authority\ // > /mnt/shared/certs/teleport.pub + sleep 10 +done diff --git a/docker/sshd/start.sh b/docker/sshd/start.sh new file mode 100755 index 00000000000..02c5c36dc8c --- /dev/null +++ b/docker/sshd/start.sh @@ -0,0 +1,4 @@ +#!/bin/bash + +syslogd& +/usr/sbin/sshd -D diff --git a/docs/testplan.md b/docs/testplan.md index 7dce0de3ddf..ed6638a5a15 100644 --- a/docs/testplan.md +++ b/docs/testplan.md @@ -7,8 +7,7 @@ as well as an upgrade of the previous version of Teleport. - [ ] Adding nodes to a cluster - [ ] Adding Nodes via Valid Static Token - [ ] Adding Nodes via Valid Short-lived Tokens - - [ ] Adding Nodes via Invalid Static Token Fails - - [ ] Adding Nodes via Invalid Short-lived Tokens Fails + - [ ] Adding Nodes via Invalid Token Fails - [ ] Revoking Node Invitation - [ ] Labels @@ -18,17 +17,22 @@ as well as an upgrade of the previous version of Teleport. - [ ] Trusted Clusters - [ ] Adding Trusted Cluster Valid Static Token - [ ] Adding Trusted Cluster Valid Short-lived Token - - [ ] Adding Trusted Cluster Invalid Static Token - - [ ] Adding Trusted Cluster Invalid Short-lived Token + - [ ] Adding Trusted Cluster Invalid Token - [ ] Removing Trusted Cluster - [ ] RBAC + + Make sure that invalid and valid attempts are reflected in audit log. + - [ ] Successfully connect to node with correct role - - [ ] Unsuccessfully connect to a role in an in-valid role + - [ ] Unsuccessfully connect to a node in a role restricting access by label + - [ ] Unsuccessfully connect to a node in a role restricting access by invalid SSH login - [ ] Allow/deny role option: SSH agent forwarding - [ ] Allow/deny role option: Port forwarding - [ ] Users +With every user combination, try to login and signup with invalid second factor, invalid password to see how the system reacts. + - [ ] Adding Users Password Only - [ ] Adding Users OTP - [ ] Adding Users U2F @@ -58,12 +62,15 @@ as well as an upgrade of the previous version of Teleport. - [ ] Failed login attempts are recorded - [ ] Interactive sessions have the correct Server ID - [ ] Server ID is the ID of the node in regular mode - - [ ] Server ID is of the proxy for proxy mode + - [ ] Server ID is randomly generated for proxy node - [ ] Exec commands are recorded - [ ] `scp` commands are recorded - [ ] Subsystem results are recorded - [ ] Interact with a cluster using `tsh` + + These commands should ideally be tested for recording and non-recording modes as they are implemented in a different ways. + - [ ] tsh ssh \ - [ ] tsh ssh \ - [ ] tsh ssh -A \ @@ -82,6 +89,7 @@ as well as an upgrade of the previous version of Teleport. - [ ] tsh clusters - [ ] Interact with a cluster using `ssh` + Make sure to test both recording and regular proxy modes. - [ ] ssh \ - [ ] ssh \ - [ ] ssh -A \ @@ -116,6 +124,14 @@ interactive sessions the 12 combinations are below. - [ ] Connect to a Teleport node in a remote cluster using Teleport. - [ ] Connect to a Teleport node in a remote cluster using the Web UI. +### Migrations + +* [ ] Migrate trusted clusters from 2.4.0 to 2.5.0 + * [ ] Migrate auth server on main cluster, then rest of the servers on main cluster + SSH should work for both main and old clusters + * [ ] Migrate auth server on remote cluster, then rest of the remote cluster + SSH should work + ### Command Templates When interacting with a cluster, the following command templates are useful: @@ -151,3 +167,4 @@ tsh --proxy=proxy.example.com --user= --insecure ssh -A -p 22 node.exa # the --cluster flag is used to connect to a node in a remote cluster. tsh --proxy=proxy.example.com --user= --insecure --cluster=foo.com ssh -p 22 node.foo.com ``` +