mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
Makes a common login error troubleshooting for sso docs (#11277)
* Incorporates a common login error troubleshooting include. Changed to show the audit log screen in the web console initially.
This commit is contained in:
Binary file not shown.
|
After Width: | Height: | Size: 445 KiB |
@@ -185,16 +185,4 @@ automatically in a browser.
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
If you get "access denied" errors, the number one place to check is the audit
|
||||
log on the Teleport Auth Server. It is located in `/var/lib/teleport/log` by
|
||||
default and it will contain the detailed reason why a user's login was denied.
|
||||
|
||||
Some errors (like filesystem permissions or misconfigured network) can be
|
||||
diagnosed using Teleport's `stderr` log, which is usually available via:
|
||||
|
||||
```bsh
|
||||
$ sudo journalctl -fu teleport
|
||||
```
|
||||
|
||||
If you wish to increase the verbosity of Teleport's syslog, you can pass
|
||||
`--debug` flag to the `teleport start` command.
|
||||
(!docs/pages/includes/sso/loginerrortroubleshooting.mdx!)
|
||||
|
||||
@@ -61,7 +61,7 @@ Before you get started you’ll need:
|
||||

|
||||
|
||||
8. For **Entity ID** and **Reply URL**, enter the same proxy URL.
|
||||
|
||||
|
||||
For self-hosted deployments, the URL will be similar to `https://teleport.example.com:3080/v1/webapi/saml/acs`.
|
||||
|
||||
For Teleport Cloud users, the URL will be similar to `https://mytenant.teleport.sh`.
|
||||
@@ -329,7 +329,7 @@ spec:
|
||||
private_key: |
|
||||
-----BEGIN RSA PRIVATE KEY-----
|
||||
New private key
|
||||
-----END RSA PRIVATE KEY-----
|
||||
-----END RSA PRIVATE KEY-----
|
||||
signing_key_pair:
|
||||
cert: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
@@ -346,7 +346,7 @@ version: v2
|
||||
Update the connector:
|
||||
|
||||
```code
|
||||
$ tctl create -f azure-out.yaml
|
||||
$ tctl create -f azure-out.yaml
|
||||
```
|
||||
|
||||
### Activate token encryption
|
||||
@@ -367,41 +367,7 @@ If the SSO login with this connector is successful, the encryption works.
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
### Access denied
|
||||
|
||||
<Tabs>
|
||||
<TabItem scope={["oss", "enterprise"]} label="Self Hosted">
|
||||
If you get "access denied" errors, the number one place to check is the audit
|
||||
log on the Teleport Auth Server. It is located in `/var/lib/teleport/log` by
|
||||
default and will contain a detailed reason why a user's login was denied.
|
||||
|
||||
Example of a user being denied because the role `clusteradmin` wasn't set up:
|
||||
|
||||
```json
|
||||
{"code":"T1001W","error":"role clusteradmin is not found","event":"user.login","method":"saml","success":false,"time":"2019-06-15T19:38:07Z","uid":"cd9e45d0-b68c-43c3-87cf-73c4e0ec37e9"}
|
||||
```
|
||||
|
||||
Some errors (like file-system permissions or a misconfigured network) can be
|
||||
diagnosed using Teleport's `stderr` log, which is usually available via:
|
||||
|
||||
```code
|
||||
$ sudo journalctl -fu teleport
|
||||
```
|
||||
|
||||
If you wish to increase the verbosity of Teleport's logs, you can pass the
|
||||
[`--debug`](../../setup/reference/cli.mdx#teleport-start) flag to the `teleport start` command.
|
||||
</TabItem>
|
||||
<TabItem scope={["cloud"]} label="Teleport Cloud">
|
||||
If you get "access denied" errors, the number one place to check is the audit
|
||||
log on the Teleport Auth Server. You can find it in the **Activity** tab of the Teleport Web UI.
|
||||
|
||||
Example of a user being denied because the role `clusteradmin` wasn't set up:
|
||||
|
||||
```json
|
||||
{"code":"T1001W","error":"role clusteradmin is not found","event":"user.login","method":"saml","success":false,"time":"2019-06-15T19:38:07Z","uid":"cd9e45d0-b68c-43c3-87cf-73c4e0ec37e9"}
|
||||
```
|
||||
</TabItem>
|
||||
</Tabs>
|
||||
(!docs/pages/includes/sso/loginerrortroubleshooting.mdx!)
|
||||
|
||||
### Failed to process SAML callback
|
||||
|
||||
@@ -420,4 +386,4 @@ Change the Name ID format to use email instead:
|
||||
|
||||
|
||||
## Further reading
|
||||
- [Teleport Configuration Resources Reference](../../setup/reference/resources.mdx)
|
||||
- [Teleport Configuration Resources Reference](../../setup/reference/resources.mdx)
|
||||
|
||||
@@ -176,16 +176,4 @@ automatically in a browser).
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
If you get "access denied errors" the number one place to check is the events in the audit
|
||||
log on the Teleport auth server. The audit events log is located in `/var/lib/teleport/log/events.log` by
|
||||
default and it will contain the detailed reason why a user's login was denied.
|
||||
|
||||
Some errors (like filesystem permissions or misconfigured network) can be
|
||||
diagnosed using Teleport's `stderr` log, which is usually available via:
|
||||
|
||||
```bsh
|
||||
$ sudo journalctl -fu teleport
|
||||
```
|
||||
|
||||
If you wish to increase the verbosity of Teleport's syslog, you can pass
|
||||
`--debug` flag to `teleport start` command.
|
||||
(!docs/pages/includes/sso/loginerrortroubleshooting.mdx!)
|
||||
|
||||
@@ -77,7 +77,7 @@ to `v3`.
|
||||

|
||||
|
||||
Configure the appearence of your connector by picking a visible name, user support email, etc.
|
||||
|
||||
|
||||
Select the `.../auth/userinfo.email` and `openid` scopes.
|
||||

|
||||
|
||||
@@ -95,7 +95,7 @@ to `v3`.
|
||||
|
||||
Pick a name for your service account. Leave project access grants and user access grants empty.
|
||||

|
||||
|
||||
|
||||
Click the newly-created account to view its details, and copy the Unique ID for later.
|
||||

|
||||
|
||||
@@ -201,36 +201,4 @@ automatically in a browser).
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
<Tabs>
|
||||
<TabItem label="Self Hosted" scope={["oss", "enterprise"]}>
|
||||
If you get "access denied" errors, the number one place to check is the audit
|
||||
log on the Teleport Auth Server. It is located in `/var/lib/teleport/log` by
|
||||
default and it will contain a detailed reason why a user's login was denied.
|
||||
|
||||
Example of a user being denied because the role `clusteradmin` wasn't set up.
|
||||
|
||||
```json
|
||||
{"code":"T1001W","error":"role clusteradmin is not found","event":"user.login","method":"oidc","success":false,"time":"2019-06-15T19:38:07Z","uid":"cd9e45d0-b68c-43c3-87cf-73c4e0ec37e9"}
|
||||
```
|
||||
|
||||
Some errors (like filesystem permissions or a misconfigured network) can be
|
||||
diagnosed using Teleport's `stderr` log, which is usually available via:
|
||||
|
||||
```code
|
||||
$ sudo journalctl -fu teleport
|
||||
```
|
||||
|
||||
If you wish to increase the verbosity of Teleport's logs, you can pass the
|
||||
[`--debug`](../../setup/reference/cli.mdx#teleport-start) flag to the `teleport start` command.
|
||||
</TabItem>
|
||||
<TabItem label="Teleport Cloud" scope={["cloud"]}>
|
||||
If you get "access denied" errors, the number one place to check is the audit
|
||||
log on the Teleport Auth Server. You can find it in the **Activity** tab of the Teleport Web UI.
|
||||
|
||||
Example of a user being denied because the role `clusteradmin` wasn't set up.
|
||||
|
||||
```json
|
||||
{"code":"T1001W","error":"role clusteradmin is not found","event":"user.login","method":"oidc","success":false,"time":"2019-06-15T19:38:07Z","uid":"cd9e45d0-b68c-43c3-87cf-73c4e0ec37e9"}
|
||||
```
|
||||
</TabItem>
|
||||
</Tabs>
|
||||
(!docs/pages/includes/sso/loginerrortroubleshooting.mdx!)
|
||||
|
||||
@@ -218,16 +218,4 @@ identity provider if you are not automatically redirected.
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
If you get "access denied errors" the number one place to check is the audit
|
||||
log on the Teleport auth server. It is located in `/var/lib/teleport/log` by
|
||||
default and it will contain the detailed reason why a user's login was denied.
|
||||
|
||||
Some errors (like filesystem permissions or misconfigured network) can be
|
||||
diagnosed using Teleport's `stderr` log, which is usually available via:
|
||||
|
||||
```bsh
|
||||
$ sudo journalctl -fu teleport
|
||||
```
|
||||
|
||||
If you wish to increase the verbosity of Teleport's syslog, you can pass
|
||||
`--debug` flag to `teleport start` command.
|
||||
(!docs/pages/includes/sso/loginerrortroubleshooting.mdx!)
|
||||
|
||||
@@ -106,11 +106,11 @@ $ tctl create okta-connector.yaml
|
||||
|
||||
## Create a Developer Teleport Role
|
||||
|
||||
We are going to create a new role that'll pull in external information from Okta. Notice
|
||||
`{{external.username}}` login. It configures Teleport to look at *"username"* Okta claim
|
||||
and use that field as an allowed login for each user. This example uses email as the
|
||||
username format. The `email.local(external.trait)` function will remove the `@domain`
|
||||
and just have the username prefix.
|
||||
We are going to create a new role that'll pull in external information from Okta. Notice
|
||||
`{{external.username}}` login. It configures Teleport to look at *"username"* Okta claim
|
||||
and use that field as an allowed login for each user. This example uses email as the
|
||||
username format. The `email.local(external.trait)` function will remove the `@domain`
|
||||
and just have the username prefix.
|
||||
|
||||
```yaml
|
||||
kind: role
|
||||
@@ -168,16 +168,4 @@ automatically in a browser).
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
If you get "access denied errors" the number one place to check is the audit
|
||||
log on the Teleport auth server. It is located in `/var/lib/teleport/log` by
|
||||
default and it will contain the detailed reason why a user's login was denied.
|
||||
|
||||
Some errors (like filesystem permissions or misconfigured network) can be
|
||||
diagnosed using Teleport's `stderr` log, which is usually available via:
|
||||
|
||||
```bsh
|
||||
$ sudo journalctl -fu teleport
|
||||
```
|
||||
|
||||
If you wish to increase the verbosity of Teleport's syslog, you can pass
|
||||
`--debug` flag to `teleport start` command.
|
||||
(!docs/pages/includes/sso/loginerrortroubleshooting.mdx!)
|
||||
|
||||
@@ -114,7 +114,7 @@ $ tctl create onelogin-connector.yaml
|
||||
## Create a new Teleport Role
|
||||
|
||||
We are going to create a new that'll use external username data from OneLogin
|
||||
to map to a host linux login.
|
||||
to map to a host linux login.
|
||||
|
||||
In the below role, Devs are only allowed to login to nodes labelled with `access: relaxed`
|
||||
Teleport label. Developers can log in as either `ubuntu` to a username that
|
||||
@@ -174,16 +174,4 @@ automatically in a browser).
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
If you get "access denied errors" the number one place to check is the audit
|
||||
log on the Teleport auth server. It is located in `/var/lib/teleport/log` by
|
||||
default and it will contain the detailed reason why a user's login was denied.
|
||||
|
||||
Some errors (like filesystem permissions or misconfigured network) can be
|
||||
diagnosed using Teleport's `stderr` log, which is usually available via:
|
||||
|
||||
```bsh
|
||||
$ sudo journalctl -fu teleport
|
||||
```
|
||||
|
||||
If you wish to increase the verbosity of Teleport's syslog, you can pass
|
||||
`--debug` flag to `teleport start` command.
|
||||
(!docs/pages/includes/sso/loginerrortroubleshooting.mdx!)
|
||||
|
||||
@@ -0,0 +1,83 @@
|
||||
<Tabs>
|
||||
<TabItem label="Self-Hosted" scope={["oss","enterprise"]}>
|
||||
|
||||
### Using the Web UI
|
||||
|
||||
If you get "access denied" or other login errors, the number one place to check is the Audit
|
||||
Log on the Teleport Auth Server. You can access it in the **Activity** tab of the Teleport Web UI.
|
||||
|
||||

|
||||
|
||||
Example of a user being denied because the role `clusteradmin` wasn't set up:
|
||||
|
||||
```json
|
||||
{
|
||||
"code": "T1001W",
|
||||
"error": "role clusteradmin is not found",
|
||||
"event": "user.login",
|
||||
"method": "oidc",
|
||||
"success": false,
|
||||
"time": "2019-06-15T19:38:07Z",
|
||||
"uid": "cd9e45d0-b68c-43c3-87cf-73c4e0ec37e9"
|
||||
}
|
||||
```
|
||||
|
||||
### On the Auth Service host
|
||||
You can monitor Audit Log file entries and process logs on the Teleport Auth Server.
|
||||
The Audit Log is located in `/var/lib/teleport/log` by
|
||||
default and it will contain a detailed reason why a user's login was denied.
|
||||
|
||||
<Admonition
|
||||
type="Note"
|
||||
title="Note"
|
||||
>
|
||||
If you are using a Teleport storage configuration that does not store log entries locally, this will not appear. You can look at the `teleport`
|
||||
process logs to see `ERROR` and `INFO` entries.
|
||||
</Admonition>
|
||||
|
||||
Example of a user being denied because the role `clusteradmin` wasn't set up:
|
||||
|
||||
|
||||
```json
|
||||
{
|
||||
"code": "T1001W",
|
||||
"error": "role clusteradmin is not found",
|
||||
"event": "user.login",
|
||||
"method": "oidc",
|
||||
"success": false,
|
||||
"time": "2019-06-15T19:38:07Z",
|
||||
"uid": "cd9e45d0-b68c-43c3-87cf-73c4e0ec37e9"
|
||||
}
|
||||
```
|
||||
|
||||
Some errors (like filesystem permissions or a misconfigured network) can be
|
||||
diagnosed using Teleport's `stderr` log, which is usually available via:
|
||||
|
||||
```code
|
||||
$ sudo journalctl -fu teleport
|
||||
```
|
||||
|
||||
If you wish to increase the verbosity of Teleport's logs, you can pass the
|
||||
[`--debug`](../../setup/reference/cli.mdx#teleport-start) flag to the `teleport start` command.
|
||||
</TabItem>
|
||||
<TabItem label="Teleport Cloud" scope={["cloud"]}>
|
||||
If you get "access denied" or other login errors, the number one place to check is the Audit
|
||||
Log on the Teleport Auth Server. You can access it in the **Activity** tab of the Teleport Web UI.
|
||||
|
||||

|
||||
|
||||
Example of a user being denied because the role `clusteradmin` wasn't set up:
|
||||
|
||||
```json
|
||||
{
|
||||
"code": "T1001W",
|
||||
"error": "role clusteradmin is not found",
|
||||
"event": "user.login",
|
||||
"method": "oidc",
|
||||
"success": false,
|
||||
"time": "2019-06-15T19:38:07Z",
|
||||
"uid": "cd9e45d0-b68c-43c3-87cf-73c4e0ec37e9"
|
||||
}
|
||||
```
|
||||
</TabItem>
|
||||
</Tabs>
|
||||
@@ -21,7 +21,7 @@ This guide explains how to set up Github Single Sign On (SSO) for Teleport.
|
||||
|
||||
Ensure that your OAuth App's "Authentication callback URL" is
|
||||
`https://PROXY_ADDRESS/v1/webapi/github/`, where `PROXY_ADDRESS` is the public
|
||||
address of the Teleport Proxy Service.
|
||||
address of the Teleport Proxy Service.
|
||||
</TabItem>
|
||||
<TabItem
|
||||
scope={["enterprise"]} label="Enterprise">
|
||||
@@ -29,7 +29,7 @@ This guide explains how to set up Github Single Sign On (SSO) for Teleport.
|
||||
|
||||
To download Teleport Enterprise, visit the
|
||||
[customer portal](https://dashboard.gravitational.com/web/login).
|
||||
|
||||
|
||||
- Create and register a GitHub OAuth App. To do so, follow the instructions in
|
||||
GitHub's documentation.
|
||||
|
||||
@@ -37,7 +37,7 @@ This guide explains how to set up Github Single Sign On (SSO) for Teleport.
|
||||
|
||||
Ensure that your OAuth App's "Authentication callback URL" is
|
||||
`https://PROXY_ADDRESS/v1/webapi/github/`, where `PROXY_ADDRESS` is the public
|
||||
address of the Teleport Proxy Service.
|
||||
address of the Teleport Proxy Service.
|
||||
</TabItem>
|
||||
<TabItem scope={["cloud"]}
|
||||
label="Cloud">
|
||||
@@ -45,7 +45,7 @@ This guide explains how to set up Github Single Sign On (SSO) for Teleport.
|
||||
- Sign up for a Teleport Cloud account. If you do not have one, visit the
|
||||
[sign up page](https://goteleport.com/signup/) to begin your free trial.
|
||||
|
||||
- Create and register a GitHub OAuth App. To do so, follow the instructions in GitHub's documentation.
|
||||
- Create and register a GitHub OAuth App. To do so, follow the instructions in GitHub's documentation.
|
||||
|
||||
[Creating an OAuth App](https://docs.github.com/en/developers/apps/building-oauth-apps/creating-an-oauth-app)
|
||||
|
||||
@@ -144,3 +144,7 @@ auth_service:
|
||||
</Details>
|
||||
|
||||
You can now log in with Teleport using GitHub SSO.
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
(!docs/pages/includes/sso/loginerrortroubleshooting.mdx!)
|
||||
|
||||
Reference in New Issue
Block a user