From aaba90047d778b86dab3396cb377bb311d06bebb Mon Sep 17 00:00:00 2001 From: Brian Joerger Date: Tue, 11 Apr 2023 10:17:23 -0700 Subject: [PATCH] * Fix Hardware Key support docs when scoped for Open Source. (#24223) * Use tctl edit for configuration example. --- .../guides/hardware-key-support.mdx | 76 ++++--------------- 1 file changed, 13 insertions(+), 63 deletions(-) diff --git a/docs/pages/access-controls/guides/hardware-key-support.mdx b/docs/pages/access-controls/guides/hardware-key-support.mdx index 89d573f6c81..c194e5c20fc 100644 --- a/docs/pages/access-controls/guides/hardware-key-support.mdx +++ b/docs/pages/access-controls/guides/hardware-key-support.mdx @@ -7,6 +7,8 @@ description: Hardware Key Support Hardware key Support is currently in Preview mode. + + Hardware Key Support requires Teleport Enterprise. By default, `tsh`, Teleport Connect, and other Teleport clients store a user's login session directly on their filesystem. If a user's filesystem is compromised, any of their active Teleport login sessions would also be compromised. @@ -77,91 +79,39 @@ spec: require_session_mfa: hardware_key_touch ``` -You can also enforce hardware key support cluster-wide by updating your Teleport configuration as below: - - - - - In the Auth Server's `teleport.yaml` file: - - ```yaml - # snippet from /etc/teleport.yaml: - auth_service: - authentication: - require_session_mfa: hardware_key_touch - ``` - - - - Obtain your existing `cluster_auth_preference` resource: - - ```code - $ tctl get cap > cap.yaml - ``` - - If you have not defined a `cluster_auth_preference`, `cap.yaml` will be blank. - - Ensure that `cap.yaml` includes the following content: - - ```yaml - kind: cluster_auth_preference - version: v2 - metadata: - name: cluster-auth-preference - spec: - type: local - require_session_mfa: hardware_key_touch - ``` - - Update the configuration: - - ```code - $ tctl create -f cap.yaml - # cluster auth preference has been updated - ``` - - - - - - - -Obtain your existing `cluster_auth_preference` resource: +You can also enforce hardware key support cluster-wide by updating your Teleport configuration: ```code -$ tctl get cap > cap.yaml +$ tctl edit cap ``` -If you have not defined a `cluster_auth_preference`, `cap.yaml` will be blank. - -Ensure that `cap.yaml` includes the following content: +Set the value of `spec.require_session_mfa` to `hardware_key_touch`: ```yaml kind: cluster_auth_preference -version: v2 metadata: + ... name: cluster-auth-preference spec: - type: local + ... require_session_mfa: hardware_key_touch + ... +version: v2 ``` -Update the configuration: +After you save and exit the editor, `tctl` will update the resource: -```code -$ tctl create -f cap.yaml -# cluster auth preference has been updated +```text +cluster auth preference has been updated ``` - - ## Step 2/2. Log In Once hardware key support is enforced, affected users will be required to have their login sessions backed by a Hardware Key for all Teleport requests. These users will be prompted to connect and touch their YubiKey on log in: - + ```code $ tsh login --user=dev --proxy=proxy.example.com:3080