diff --git a/docs/img/headless/approval.png b/docs/img/headless/approval.png new file mode 100644 index 00000000000..dce71a9a6e8 Binary files /dev/null and b/docs/img/headless/approval.png differ diff --git a/docs/img/headless/confirmation.png b/docs/img/headless/confirmation.png new file mode 100644 index 00000000000..963d55258f7 Binary files /dev/null and b/docs/img/headless/confirmation.png differ diff --git a/docs/pages/access-controls/guides/headless.mdx b/docs/pages/access-controls/guides/headless.mdx index 3fd5b304403..fd021da4378 100644 --- a/docs/pages/access-controls/guides/headless.mdx +++ b/docs/pages/access-controls/guides/headless.mdx @@ -35,6 +35,7 @@ For example: - Machines for Headless WebAuthn activities have [Linux](../../installation.mdx#linux), [macOS](../../installation.mdx#macos) or [Windows](../../installation.mdx#windows-tsh-client-only) `tsh` binary v12.2+ installed. - Machines used to approve Headless WebAuthn requests have a Web browser with [WebAuthn support]( https://developers.yubico.com/WebAuthn/WebAuthn_Browser_Support/) or `tsh` binary v12.2+ installed. +- Optional: Teleport Connect v13.3.1+ for [seamless Headless WebAuthn approval](#optional-teleport-connect). ## Step 1/3. Configuration @@ -178,6 +179,25 @@ alice@server01 $ your local terminal. +## Optional: Teleport Connect + +Teleport Connect v13.3.1+ can also be used to approve Headless WebAuthn logins. +Teleport Connect will automatically detect the Headless WebAuthn login attempt +and allow you to approve or cancel the request. + +
+![Headless Confirmation](../../../img/headless/confirmation.png) +
+ +You will be prompted to tap your MFA key to complete the approval process. + +
+![Headless WebAuthn Approval](../../../img/headless/approval.png) +
+ + + This also requires a v13.3.1+ Teleport Auth Service. + ## Troubleshooting diff --git a/docs/pages/connect-your-client/teleport-connect.mdx b/docs/pages/connect-your-client/teleport-connect.mdx index cf01e40e3b6..a743585ac2e 100644 --- a/docs/pages/connect-your-client/teleport-connect.mdx +++ b/docs/pages/connect-your-client/teleport-connect.mdx @@ -212,6 +212,7 @@ Below is the list of the supported config properties. | `keymap.openClusters` | `Command+E` on macOS
`Ctrl+E` on Windows/Linux | Shortcut to open the cluster selector. | | `keymap.openProfiles` | `Command+I` on macOS
`Ctrl+I` on Windows/Linux | Shortcut to open the profile selector. | | `keymap.openSearchBar` | `Command+K` on macOS
`Ctrl+K` on Windows/Linux | Shortcut to open the search bar. | +| `headless.skipConfirm` | false | Skips the confirmation prompt for Headless WebAuthn approval and instead prompts for WebAuthn immediately. |