Commit Graph
1511 Commits
Author SHA1 Message Date
Sasha Klizhentas 4b39fcf4d2 couple of UX tweaks 2017-11-29 11:28:24 -08:00
Sasha Klizhentas b1f502a0f3 add ttl support for invite tokens, fixes #1474 2017-11-28 19:39:12 -08:00
Sasha Klizhentas 5778537999 Merge branch 'master' into sasha/mux 2017-11-26 13:59:46 -08:00
Sasha Klizhentas 5c3139f111 add comment to explain two attempts 2017-11-26 13:53:30 -08:00
Roman Tkachenko 02c027d2ea Fix trusted cluster extension schema 2017-11-24 13:35:41 -08:00
Sasha Klizhentas f8dba76147 SSH/TLS multiplexer with Proxy protocol support
This commit aadds multiplexer library of SSH/TLS on the same
listener socket. The multiplexer detects the protocol by the first
3 bytes of the incoming connection and forwards wrapped
connection either to the SSH ot TLS listeners.

The library also supports PROXY line protocol
and wraps connection information with connection details
from the proxy line received by the server
2017-11-23 14:50:28 -08:00
Roman Tkachenko 143b834e57 Changes for the upcoming teleport pro:
* Allow external audit log plugins
* Add support for auth API server plugins
* Add license file path configuration parameter (not used in open-source)
* Extend audit log with user login events
2017-11-21 17:35:58 -08:00
Sasha Klizhentas ab7bb2862d add comments 2017-11-21 16:11:34 -08:00
Sasha Klizhentas c4a72fd353 add rule checks and evaluation priorities
This commit improves error handling and improves rule evaluatons
by introducing rule priorities.

Roles are now checked for syntax errors in 'where' and 'actions'
sections what was not done before.

In case if several equivalent rules are specified, new rule
evaluations are now going into effect:

More specific rule will be matched first.

* Rule matching wildcard resource is less specific
than same rule matching specific resourc
* Rule that has wildcard verbs is less specific
than the same rules matching specific verb
* Rule that has where section is more specific
than the same rule without where section
* Rule that has actions list is more specific than
rule without actions list.
2017-11-21 15:15:09 -08:00
Sasha Klizhentas db4952b788 revendor trace and logger, fixes #1450 2017-11-20 12:08:56 -08:00
Sasha Klizhentas 315ba11654 fixes issue with race on closed listener 2017-11-17 18:30:02 -08:00
Sasha Klizhentas f8c715ef41 make audit accessible by admin group members
If user running teleport is a member of adm group
create the directory and all subdirectories
accessible to admins.

Remove obsolete migrations required for pre 2.3 releases.
2017-11-17 17:58:34 -08:00
Sasha Klizhentas 4089574f53 fix delays and offsets, address review comments 2017-11-16 14:43:35 -08:00
Sasha Klizhentas 965c0e2848 address code review changes 2017-11-16 10:31:52 -08:00
Sasha Klizhentas fed7d2f116 fix audit log file leak, fixes #1433
This is a fix for file leak in audit log server caused
by design issue:

Session file descriptors in audit log were opened on demand
when the session event or byte stream chunk  was reported.

AuditLog server relied on SessionEnd event to close the
file descriptors associated with the session.

However, when SessionEnd event does not arrive (e.g.
there is a timeout or disconnect), the file descriptors
were not closed. This commit adds periodic clean up
of inactive sessions.

SessionEnd is now used as an optimization measure
to close the files, but is not used as the only
trigger to close files.

Now, inactive idle sessions, will close file descriptors
after periods of inactivity and will reopen the file
descriptors when the session activity resumes.

SessionLogger was not designed to open/close files
multiple times as it was reseting offsets
every time the session files were opened. This
change fixes this condition as well.
2017-11-15 18:39:27 -08:00
Russell Jones 9ad600d39b Forwarding to proxy is controlled by a global out-of-band
request. Always forward Teleport agent to node in Web UI.
Support the -A flag in tsh to optionally forward agent to
node in CLI.
2017-11-16 00:11:25 +00:00
Russell Jones ad041465e2 Code review comments. 2017-11-15 19:25:21 +00:00
Russell Jones d346c10c37 Consolidate and refactor authorization and authentication handlers. 2017-11-14 16:43:33 -08:00
Sasha Klizhentas 43c2515f8c address code review comments 2017-11-13 10:10:04 -08:00
Sasha Klizhentas e9599f2138 Merge branch 'master' into sasha/dynamo 2017-11-13 09:53:43 -08:00
Sasha Klizhentas 461341651c adjust session TTL for requested certs 2017-11-10 15:22:04 -08:00
Sasha Klizhentas f2549155fd Update DynamoDB backend
* Add support for TTL
* Add support for Batch reads
* Update default values
* Use batch reads to retrieve nodes
2017-11-10 12:20:18 -08:00
Russell Jones 1eb6f6bd52 Refactored lib/srv to support multiple servers. 2017-11-09 16:58:58 -08:00
Russell Jones 38e0e13d42 Cache services.ClusterConfig in AuthServer so it can be looked up by
every request in the API server.
2017-11-02 15:06:41 -07:00
sokoow 56f778a19d Fixes for https://github.com/gravitational/teleport/pull/1426 2017-11-01 21:03:20 +00:00
sokoow a737326042 Adding disable-tls flag, fixing https://github.com/gravitational/teleport/issues/1304 2017-11-01 21:03:20 +00:00
Russell Jones 146220e3c9 Set default cluster configuration when not specified. 2017-10-31 11:03:29 -07:00
Maximilien Richer cbca7fe984 Merge branch 'master' into fix-typo 2017-10-27 17:29:13 +02:00
Russell Jones 4765e32473 Updated ClusterConfig to V3. 2017-10-26 12:34:51 -07:00
Russell Jones 432a7ad787 Added services.ClusterConfig resource which controls where (and if) a
session is recorded.
2017-10-25 21:09:21 +00:00
mricher b58cb051e8 Correct various typos
This was fixed running the `misspell` linter in fix mode using
`gometalinter`. The exact command I ran was :
```
gometalinter --vendor --disable-all -E misspell --linter='misspell:misspell -w {path}:^(?P<path>.*?\.go):(?P<line>\d+):(?P<col>\d+):\s*(?P<message>.*)$' ./...
```

Some typo were fixed by hand on top of it.
2017-10-20 10:20:26 +02:00
Sasha Klizhentas 7b87c73f6b fix cluster name fix 2017-10-19 00:36:32 +00:00
Russell Jones 3634291bd9 Add ClusterName to discovery request. 2017-10-19 00:36:03 +00:00
Roman Tkachenko 67087b81de Merge branch 'master' into roman/plugins 2017-10-17 09:32:28 -07:00
Alexey Kontsevoy 992b953a8c Merge branch 'master' of github.com:gravitational/teleport into fixes 2017-10-16 20:38:06 -04:00
Alexey Kontsevoy 24f1312c16 use hostname to find an existing server 2017-10-16 20:37:13 -04:00
Ev Kontsevoy 33b5cf0fcb Removed oidc_connectors from sample configuration
Problem:

`teleport configure` prints `oidc_connectors` for sample configuration
file (even for OSS version).

This property has been deprecated long time ago. I added 'omitempty' to
JSON serialization.
2017-10-16 17:30:21 -07:00
Roman Tkachenko 96a249de14 Rename plugins to modules 2017-10-16 16:55:39 -07:00
Roman Tkachenko 764db9d015 Add test 2017-10-16 13:49:30 -07:00
Roman Tkachenko d127c4fdb6 Merge branch 'master' into roman/plugins 2017-10-16 11:42:42 -07:00
Roman Tkachenko 668243d144 Plugins interface 2017-10-16 11:42:01 -07:00
Sasha Klizhentas 0938ce2dfb fix typo 2017-10-16 09:38:06 -07:00
Sasha Klizhentas 13e23a8b67 Merge branch 'master' into sasha/curiosity 2017-10-13 19:27:28 -07:00
Sasha Klizhentas 039249507d update according to code review comments 2017-10-13 19:26:49 -07:00
Roman Tkachenko 5dbda4f41b Use plugins mechanism instead of oss/e flag 2017-10-13 17:32:45 -07:00
Russell Jones 7a46471553 Validate self-signed certificates upon startup correctly. 2017-10-13 22:19:21 +00:00
Alexey Kontsevoy c6f42c49d9 adding password change API endpoint 2017-10-13 17:02:40 -04:00
Sasha Klizhentas d69f88978b fix data race in tun client 2017-10-13 11:51:14 -07:00
Sasha Klizhentas 4b36d77f31 remove data race on channel close 2017-10-13 10:21:10 -07:00
Sasha Klizhentas 6471bc32da fix data race 2017-10-13 09:11:13 -07:00