This commit aadds multiplexer library of SSH/TLS on the same
listener socket. The multiplexer detects the protocol by the first
3 bytes of the incoming connection and forwards wrapped
connection either to the SSH ot TLS listeners.
The library also supports PROXY line protocol
and wraps connection information with connection details
from the proxy line received by the server
* Allow external audit log plugins
* Add support for auth API server plugins
* Add license file path configuration parameter (not used in open-source)
* Extend audit log with user login events
This commit improves error handling and improves rule evaluatons
by introducing rule priorities.
Roles are now checked for syntax errors in 'where' and 'actions'
sections what was not done before.
In case if several equivalent rules are specified, new rule
evaluations are now going into effect:
More specific rule will be matched first.
* Rule matching wildcard resource is less specific
than same rule matching specific resourc
* Rule that has wildcard verbs is less specific
than the same rules matching specific verb
* Rule that has where section is more specific
than the same rule without where section
* Rule that has actions list is more specific than
rule without actions list.
If user running teleport is a member of adm group
create the directory and all subdirectories
accessible to admins.
Remove obsolete migrations required for pre 2.3 releases.
This is a fix for file leak in audit log server caused
by design issue:
Session file descriptors in audit log were opened on demand
when the session event or byte stream chunk was reported.
AuditLog server relied on SessionEnd event to close the
file descriptors associated with the session.
However, when SessionEnd event does not arrive (e.g.
there is a timeout or disconnect), the file descriptors
were not closed. This commit adds periodic clean up
of inactive sessions.
SessionEnd is now used as an optimization measure
to close the files, but is not used as the only
trigger to close files.
Now, inactive idle sessions, will close file descriptors
after periods of inactivity and will reopen the file
descriptors when the session activity resumes.
SessionLogger was not designed to open/close files
multiple times as it was reseting offsets
every time the session files were opened. This
change fixes this condition as well.
This was fixed running the `misspell` linter in fix mode using
`gometalinter`. The exact command I ran was :
```
gometalinter --vendor --disable-all -E misspell --linter='misspell:misspell -w {path}:^(?P<path>.*?\.go):(?P<line>\d+):(?P<col>\d+):\s*(?P<message>.*)$' ./...
```
Some typo were fixed by hand on top of it.
Problem:
`teleport configure` prints `oidc_connectors` for sample configuration
file (even for OSS version).
This property has been deprecated long time ago. I added 'omitempty' to
JSON serialization.