Makes a common login error troubleshooting for sso docs (#11277)

* Incorporates a common login error troubleshooting include. Changed to show
the audit log screen in the web console initially.
This commit is contained in:
Steven Martin
2022-03-27 02:38:27 +00:00
committed by GitHub
parent 90dde13ef0
commit f00a4e2b66
10 changed files with 110 additions and 149 deletions
Binary file not shown.

After

Width:  |  Height:  |  Size: 445 KiB

+1 -13
View File
@@ -185,16 +185,4 @@ automatically in a browser.
## Troubleshooting
If you get "access denied" errors, the number one place to check is the audit
log on the Teleport Auth Server. It is located in `/var/lib/teleport/log` by
default and it will contain the detailed reason why a user's login was denied.
Some errors (like filesystem permissions or misconfigured network) can be
diagnosed using Teleport's `stderr` log, which is usually available via:
```bsh
$ sudo journalctl -fu teleport
```
If you wish to increase the verbosity of Teleport's syslog, you can pass
`--debug` flag to the `teleport start` command.
(!docs/pages/includes/sso/loginerrortroubleshooting.mdx!)
+5 -39
View File
@@ -61,7 +61,7 @@ Before you get started you’ll need:
![Edit Basic SAML Configuration](../../../img/azuread/azuread-7-editbasicsaml.png)
8. For **Entity ID** and **Reply URL**, enter the same proxy URL.
For self-hosted deployments, the URL will be similar to `https://teleport.example.com:3080/v1/webapi/saml/acs`.
For Teleport Cloud users, the URL will be similar to `https://mytenant.teleport.sh`.
@@ -329,7 +329,7 @@ spec:
private_key: |
-----BEGIN RSA PRIVATE KEY-----
New private key
-----END RSA PRIVATE KEY-----
-----END RSA PRIVATE KEY-----
signing_key_pair:
cert: |
-----BEGIN CERTIFICATE-----
@@ -346,7 +346,7 @@ version: v2
Update the connector:
```code
$ tctl create -f azure-out.yaml
$ tctl create -f azure-out.yaml
```
### Activate token encryption
@@ -367,41 +367,7 @@ If the SSO login with this connector is successful, the encryption works.
## Troubleshooting
### Access denied
<Tabs>
<TabItem scope={["oss", "enterprise"]} label="Self Hosted">
If you get "access denied" errors, the number one place to check is the audit
log on the Teleport Auth Server. It is located in `/var/lib/teleport/log` by
default and will contain a detailed reason why a user's login was denied.
Example of a user being denied because the role `clusteradmin` wasn't set up:
```json
{"code":"T1001W","error":"role clusteradmin is not found","event":"user.login","method":"saml","success":false,"time":"2019-06-15T19:38:07Z","uid":"cd9e45d0-b68c-43c3-87cf-73c4e0ec37e9"}
```
Some errors (like file-system permissions or a misconfigured network) can be
diagnosed using Teleport's `stderr` log, which is usually available via:
```code
$ sudo journalctl -fu teleport
```
If you wish to increase the verbosity of Teleport's logs, you can pass the
[`--debug`](../../setup/reference/cli.mdx#teleport-start) flag to the `teleport start` command.
</TabItem>
<TabItem scope={["cloud"]} label="Teleport Cloud">
If you get "access denied" errors, the number one place to check is the audit
log on the Teleport Auth Server. You can find it in the **Activity** tab of the Teleport Web UI.
Example of a user being denied because the role `clusteradmin` wasn't set up:
```json
{"code":"T1001W","error":"role clusteradmin is not found","event":"user.login","method":"saml","success":false,"time":"2019-06-15T19:38:07Z","uid":"cd9e45d0-b68c-43c3-87cf-73c4e0ec37e9"}
```
</TabItem>
</Tabs>
(!docs/pages/includes/sso/loginerrortroubleshooting.mdx!)
### Failed to process SAML callback
@@ -420,4 +386,4 @@ Change the Name ID format to use email instead:
## Further reading
- [Teleport Configuration Resources Reference](../../setup/reference/resources.mdx)
- [Teleport Configuration Resources Reference](../../setup/reference/resources.mdx)
+1 -13
View File
@@ -176,16 +176,4 @@ automatically in a browser).
## Troubleshooting
If you get "access denied errors" the number one place to check is the events in the audit
log on the Teleport auth server. The audit events log is located in `/var/lib/teleport/log/events.log` by
default and it will contain the detailed reason why a user's login was denied.
Some errors (like filesystem permissions or misconfigured network) can be
diagnosed using Teleport's `stderr` log, which is usually available via:
```bsh
$ sudo journalctl -fu teleport
```
If you wish to increase the verbosity of Teleport's syslog, you can pass
`--debug` flag to `teleport start` command.
(!docs/pages/includes/sso/loginerrortroubleshooting.mdx!)
+3 -35
View File
@@ -77,7 +77,7 @@ to `v3`.
![configuration of the OAuth consent screen](../../../img/googleoidc/consent-screen-1.png)
Configure the appearence of your connector by picking a visible name, user support email, etc.
Select the `.../auth/userinfo.email` and `openid` scopes.
![select email and openid scopes](../../../img/googleoidc/consent-screen-2.png)
@@ -95,7 +95,7 @@ to `v3`.
Pick a name for your service account. Leave project access grants and user access grants empty.
![service account creation](../../../img/googleoidc/serviceacct-creation.png)
Click the newly-created account to view its details, and copy the Unique ID for later.
![service account unique ID](../../../img/googleoidc/serviceacct-uniqueid.png)
@@ -201,36 +201,4 @@ automatically in a browser).
## Troubleshooting
<Tabs>
<TabItem label="Self Hosted" scope={["oss", "enterprise"]}>
If you get "access denied" errors, the number one place to check is the audit
log on the Teleport Auth Server. It is located in `/var/lib/teleport/log` by
default and it will contain a detailed reason why a user's login was denied.
Example of a user being denied because the role `clusteradmin` wasn't set up.
```json
{"code":"T1001W","error":"role clusteradmin is not found","event":"user.login","method":"oidc","success":false,"time":"2019-06-15T19:38:07Z","uid":"cd9e45d0-b68c-43c3-87cf-73c4e0ec37e9"}
```
Some errors (like filesystem permissions or a misconfigured network) can be
diagnosed using Teleport's `stderr` log, which is usually available via:
```code
$ sudo journalctl -fu teleport
```
If you wish to increase the verbosity of Teleport's logs, you can pass the
[`--debug`](../../setup/reference/cli.mdx#teleport-start) flag to the `teleport start` command.
</TabItem>
<TabItem label="Teleport Cloud" scope={["cloud"]}>
If you get "access denied" errors, the number one place to check is the audit
log on the Teleport Auth Server. You can find it in the **Activity** tab of the Teleport Web UI.
Example of a user being denied because the role `clusteradmin` wasn't set up.
```json
{"code":"T1001W","error":"role clusteradmin is not found","event":"user.login","method":"oidc","success":false,"time":"2019-06-15T19:38:07Z","uid":"cd9e45d0-b68c-43c3-87cf-73c4e0ec37e9"}
```
</TabItem>
</Tabs>
(!docs/pages/includes/sso/loginerrortroubleshooting.mdx!)
+1 -13
View File
@@ -218,16 +218,4 @@ identity provider if you are not automatically redirected.
## Troubleshooting
If you get "access denied errors" the number one place to check is the audit
log on the Teleport auth server. It is located in `/var/lib/teleport/log` by
default and it will contain the detailed reason why a user's login was denied.
Some errors (like filesystem permissions or misconfigured network) can be
diagnosed using Teleport's `stderr` log, which is usually available via:
```bsh
$ sudo journalctl -fu teleport
```
If you wish to increase the verbosity of Teleport's syslog, you can pass
`--debug` flag to `teleport start` command.
(!docs/pages/includes/sso/loginerrortroubleshooting.mdx!)
+6 -18
View File
@@ -106,11 +106,11 @@ $ tctl create okta-connector.yaml
## Create a Developer Teleport Role
We are going to create a new role that'll pull in external information from Okta. Notice
`{{external.username}}` login. It configures Teleport to look at *"username"* Okta claim
and use that field as an allowed login for each user. This example uses email as the
username format. The `email.local(external.trait)` function will remove the `@domain`
and just have the username prefix.
We are going to create a new role that'll pull in external information from Okta. Notice
`{{external.username}}` login. It configures Teleport to look at *"username"* Okta claim
and use that field as an allowed login for each user. This example uses email as the
username format. The `email.local(external.trait)` function will remove the `@domain`
and just have the username prefix.
```yaml
kind: role
@@ -168,16 +168,4 @@ automatically in a browser).
## Troubleshooting
If you get "access denied errors" the number one place to check is the audit
log on the Teleport auth server. It is located in `/var/lib/teleport/log` by
default and it will contain the detailed reason why a user's login was denied.
Some errors (like filesystem permissions or misconfigured network) can be
diagnosed using Teleport's `stderr` log, which is usually available via:
```bsh
$ sudo journalctl -fu teleport
```
If you wish to increase the verbosity of Teleport's syslog, you can pass
`--debug` flag to `teleport start` command.
(!docs/pages/includes/sso/loginerrortroubleshooting.mdx!)
+2 -14
View File
@@ -114,7 +114,7 @@ $ tctl create onelogin-connector.yaml
## Create a new Teleport Role
We are going to create a new that'll use external username data from OneLogin
to map to a host linux login.
to map to a host linux login.
In the below role, Devs are only allowed to login to nodes labelled with `access: relaxed`
Teleport label. Developers can log in as either `ubuntu` to a username that
@@ -174,16 +174,4 @@ automatically in a browser).
## Troubleshooting
If you get "access denied errors" the number one place to check is the audit
log on the Teleport auth server. It is located in `/var/lib/teleport/log` by
default and it will contain the detailed reason why a user's login was denied.
Some errors (like filesystem permissions or misconfigured network) can be
diagnosed using Teleport's `stderr` log, which is usually available via:
```bsh
$ sudo journalctl -fu teleport
```
If you wish to increase the verbosity of Teleport's syslog, you can pass
`--debug` flag to `teleport start` command.
(!docs/pages/includes/sso/loginerrortroubleshooting.mdx!)
@@ -0,0 +1,83 @@
<Tabs>
<TabItem label="Self-Hosted" scope={["oss","enterprise"]}>
### Using the Web UI
If you get "access denied" or other login errors, the number one place to check is the Audit
Log on the Teleport Auth Server. You can access it in the **Activity** tab of the Teleport Web UI.
![Audit Log Entry for SSO Login error](../../../img/sso/teleportauditlogssofailed.png)
Example of a user being denied because the role `clusteradmin` wasn't set up:
```json
{
"code": "T1001W",
"error": "role clusteradmin is not found",
"event": "user.login",
"method": "oidc",
"success": false,
"time": "2019-06-15T19:38:07Z",
"uid": "cd9e45d0-b68c-43c3-87cf-73c4e0ec37e9"
}
```
### On the Auth Service host
You can monitor Audit Log file entries and process logs on the Teleport Auth Server.
The Audit Log is located in `/var/lib/teleport/log` by
default and it will contain a detailed reason why a user's login was denied.
<Admonition
type="Note"
title="Note"
>
If you are using a Teleport storage configuration that does not store log entries locally, this will not appear. You can look at the `teleport`
process logs to see `ERROR` and `INFO` entries.
</Admonition>
Example of a user being denied because the role `clusteradmin` wasn't set up:
```json
{
"code": "T1001W",
"error": "role clusteradmin is not found",
"event": "user.login",
"method": "oidc",
"success": false,
"time": "2019-06-15T19:38:07Z",
"uid": "cd9e45d0-b68c-43c3-87cf-73c4e0ec37e9"
}
```
Some errors (like filesystem permissions or a misconfigured network) can be
diagnosed using Teleport's `stderr` log, which is usually available via:
```code
$ sudo journalctl -fu teleport
```
If you wish to increase the verbosity of Teleport's logs, you can pass the
[`--debug`](../../setup/reference/cli.mdx#teleport-start) flag to the `teleport start` command.
</TabItem>
<TabItem label="Teleport Cloud" scope={["cloud"]}>
If you get "access denied" or other login errors, the number one place to check is the Audit
Log on the Teleport Auth Server. You can access it in the **Activity** tab of the Teleport Web UI.
![Audit Log Entry for SSO Login error](../../../img/sso/teleportauditlogssofailed.png)
Example of a user being denied because the role `clusteradmin` wasn't set up:
```json
{
"code": "T1001W",
"error": "role clusteradmin is not found",
"event": "user.login",
"method": "oidc",
"success": false,
"time": "2019-06-15T19:38:07Z",
"uid": "cd9e45d0-b68c-43c3-87cf-73c4e0ec37e9"
}
```
</TabItem>
</Tabs>
+8 -4
View File
@@ -21,7 +21,7 @@ This guide explains how to set up Github Single Sign On (SSO) for Teleport.
Ensure that your OAuth App's "Authentication callback URL" is
`https://PROXY_ADDRESS/v1/webapi/github/`, where `PROXY_ADDRESS` is the public
address of the Teleport Proxy Service.
address of the Teleport Proxy Service.
</TabItem>
<TabItem
scope={["enterprise"]} label="Enterprise">
@@ -29,7 +29,7 @@ This guide explains how to set up Github Single Sign On (SSO) for Teleport.
To download Teleport Enterprise, visit the
[customer portal](https://dashboard.gravitational.com/web/login).
- Create and register a GitHub OAuth App. To do so, follow the instructions in
GitHub's documentation.
@@ -37,7 +37,7 @@ This guide explains how to set up Github Single Sign On (SSO) for Teleport.
Ensure that your OAuth App's "Authentication callback URL" is
`https://PROXY_ADDRESS/v1/webapi/github/`, where `PROXY_ADDRESS` is the public
address of the Teleport Proxy Service.
address of the Teleport Proxy Service.
</TabItem>
<TabItem scope={["cloud"]}
label="Cloud">
@@ -45,7 +45,7 @@ This guide explains how to set up Github Single Sign On (SSO) for Teleport.
- Sign up for a Teleport Cloud account. If you do not have one, visit the
[sign up page](https://goteleport.com/signup/) to begin your free trial.
- Create and register a GitHub OAuth App. To do so, follow the instructions in GitHub's documentation.
- Create and register a GitHub OAuth App. To do so, follow the instructions in GitHub's documentation.
[Creating an OAuth App](https://docs.github.com/en/developers/apps/building-oauth-apps/creating-an-oauth-app)
@@ -144,3 +144,7 @@ auth_service:
</Details>
You can now log in with Teleport using GitHub SSO.
## Troubleshooting
(!docs/pages/includes/sso/loginerrortroubleshooting.mdx!)