Commit Graph
471 Commits
Author SHA1 Message Date
Andrew Lytvynov b1eae4ac4c Remove unused functions and methods throughout lib/...
This code is not caught by linters because it's exported and they assume
there's some external users.
Since teleport is relatively self-contained, we can tell for sure
whether something is called or not.
2020-05-06 00:02:53 +00:00
Lisa Kim 118ad19101 Emit correct event user who updates user records (#3635)
* Add UpdateUser rpc to proto
* Differentiate between create and update in github,oidc,saml
* Edit updated_by event field to be more generic (used with contexts to capture user modifying records)
* Update security issue by removing secrets from user when update/upsert/create (forrest)
* Update createUser in resource_command and require force for updates
2020-05-05 16:49:32 -07:00
Andrew Lytvynov c840f16c42 Fix staticcheck findings in lib/web/...
Fixed issues:
```
lib/web/apiserver_test.go:499:2: SA4006: this value of `re` is never used (staticcheck)
	re, err = pack.clt.Get(context.Background(), pack.clt.Endpoint("webapi", "sites"), url.Values{})
	^
lib/web/apiserver_test.go:590:2: SA4006: this value of `re` is never used (staticcheck)
	re, err = newPack.clt.Get(context.Background(), pack.clt.Endpoint("webapi", "sites"), url.Values{})
	^
lib/web/apiserver_test.go:598:2: SA4006: this value of `re` is never used (staticcheck)
	re, err = oldClt.Get(context.Background(), pack.clt.Endpoint("webapi", "sites"), url.Values{})
	^
lib/web/apiserver_test.go:608:2: SA4006: this value of `re` is never used (staticcheck)
	re, err = newPack.clt.Get(context.Background(), pack.clt.Endpoint("webapi", "sites"), url.Values{})
	^
lib/web/apiserver_test.go:1106:2: SA4006: this value of `err` is never used (staticcheck)
	loginReq, err := json.Marshal(createSessionReq{
	^
lib/web/apiserver_test.go:1120:2: SA4006: this value of `err` is never used (staticcheck)
	re, err := clt.Client.RoundTrip(func() (*http.Response, error) {
	^
lib/web/apiserver_test.go:1148:2: SA4006: this value of `re` is never used (staticcheck)
	re, err = clt.Get(context.Background(), clt.Endpoint("webapi", "sites"), url.Values{})
	^
lib/web/apiserver_test.go:1154:2: SA4006: this value of `re` is never used (staticcheck)
	re, err = clt.Get(context.Background(), clt.Endpoint("webapi", "sites"), url.Values{})
	^
lib/web/apiserver_test.go:1192:2: SA4006: this value of `err` is never used (staticcheck)
	data, err := json.Marshal(auth.ChangePasswordWithTokenRequest{
	^
lib/web/apiserver_test.go:1206:2: SA4006: this value of `err` is never used (staticcheck)
	re, err = clt.Client.RoundTrip(func() (*http.Response, error) {
	^
lib/web/apiserver_test.go:1246:2: SA4006: this value of `err` is never used (staticcheck)
	data, err := json.Marshal(auth.ChangePasswordWithTokenRequest{
	^
lib/web/apiserver_test.go:1260:2: SA4006: this value of `err` is never used (staticcheck)
	re, err = clt.Client.RoundTrip(func() (*http.Response, error) {
	^
lib/web/static_test.go:93:2: SA4006: this value of `n` is never used (staticcheck)
	n, err = f.Seek(-50, io.SeekEnd)
	^
lib/web/static_test.go:100:2: SA4006: this value of `n` is never used (staticcheck)
	n, err = f.Seek(-50, io.SeekCurrent)
	^
```
2020-04-28 15:17:44 +00:00
Andrew Lytvynov 7ccdd87496 Enable more Go linters: varcheck,bodyclose,structcheck
All changes should be noop, except for
`integration/integration_test.go`.

The integration test was ignoring `recordingMode` test case parameter
and always used `RecordAtNode`. When switching to `recordingMode`, test
cases with `RecordAtProxy` fail with a confusing error about missing
user agent. Filed https://github.com/gravitational/teleport/issues/3606
to track that separately and unblock enabling `structcheck` linter.
2020-04-24 15:52:43 +00:00
Lisa Kim 6bb9ef65fa Define create user rpc and event (#3602)
* Define a CreateUser event, code, and its related const
* Define CreateUser rpc in auth/proto file
* Define CreateUser between layers
* Replace UpsertUser with CreateUser in tctl and in unit test
2020-04-22 13:04:40 -07:00
Andrew Lytvynov d1ea40d074 Enable linters: deadcode,goimports,govet,typecheck
And fix the relevant findings for these linters.

Also, set extra flags for `golangci-lint run` to make sure no findings
are suppressed.
2020-04-17 17:46:51 +00:00
Lisa Kim c5ca671d67 Emit node hostname as part of session.end event (#3595)
* Test active Session fields are populated
2020-04-16 17:14:47 -07:00
Lisa Kim 1606b30281 Wrap error from u2f library with Trace.BadParameter when registry fails (#3592)
* Removed proxy/auth version mismatch check
2020-04-16 15:32:26 -07:00
3c670d5d58 Merge Teleport V4.3 UI branch to master (#3583)
* Add monorepo

* Add reset/passwd capability for local users (#3287)

* Add UserTokens to allow password resets

* Pass context down through ChangePasswordWithToken

* Rename UserToken to ResetPasswordToken

* Add auto formatting for proto files

* Add common Marshaller interfaces to reset password token

* Allow enterprise "tctl" reuse OSS user methods (#3344)

* Pass localAuthEnabled flag to UI (#3412)

* Added LocalAuthEnabled prop to WebConfigAuthSetting struct in webconfig.go
* Added LocalAuthEnabled state as part of webCfg in  apiserver.go

* update e-refs

* Fix a regression bug after merge

* Update tctl CLI output msgs (#3442)

* Use local user client when resolving user roles

* Update webapps ref

* Add and retrieve fields from Cluster struct (#3476)

* Set Teleport versions for node, auth, proxy init heartbeat
* Add and retrieve fields NodeCount, PublicURL, AuthVersion from Clusters
* Remove debug logging to avoid log pollution when getting public_addr of proxy
* Create helper func GuessProxyHost to get the public_addr of a proxy host
* Refactor newResetPasswordToken to use GuessProxyHost and remove publicUrl func

* Remove webapps submodule

* Add webassets submodule

* Replace webapps sub-module reference with webassets

* Update webassets path in Makefile

* Update webassets

1b11b26 Simplify and clean up Makefile (#62) https://github.com/gravitational/webapps/commit/1b11b26

* Retrieve cluster details for user context (#3515)

* Let GuessProxyHost also return proxy's version
* Unit test GuessProxyHostAndVersion & GetClusterDetails

* Update webassets

4dfef4e Fix build pipeline (#66) https://github.com/gravitational/webapps/commit/4dfef4e

* Update e-ref

* Update webassets

0647568 Fix OSS redirects https://github.com/gravitational/webapps/commit/0647568

* update e-ref

* Update webassets

e0f4189 Address security audit warnings Updates  "minimist" package which is used by 7y old "optimist". https://github.com/gravitational/webapps/commit/e0f4189

* Add new attr to Session struct (#3574)

* Add fields ServerHostname and ServerAddr
* Set these fields on newSession

* Ensure webassets submodule during build

* Update e-ref

* Ensure webassets before running unit-tests

* Update E-ref

Co-authored-by: Lisa Kim <lisa@gravitational.com>
Co-authored-by: Pierre Beaucamp <pierre@gravitational.com>
Co-authored-by: Jenkins <jenkins@gravitational.io>
2020-04-15 15:35:26 -04:00
Andrew Lytvynov f8661edea3 Clean up dead code across the codebase
Spring cleaning!
A very mechanical cleanup using several linters (unused, deadcode,
structcheck). Build and tests still pass so no behavior should be
affected.
2020-04-09 21:10:12 +00:00
Lisa Kim ed72863ccb Add temporary check for mismatch proxy/auth version (#3462)
* Add temp. check for mismatch proxy/auth version

* Follow standard for making code temporary

* Rename confusing variable names

* Add rolling version and modify message
2020-03-27 08:53:04 -07:00
Lars Lehtonen 4aa06fdfe7 lib/web: WebSuite.TestSAMLSuccess() fix dropped test errors 2020-03-26 16:52:26 -07:00
Lars Lehtonen 86ed0c90ca lib/web: WebSuite.TestResizeTerminal() fix dropped test error 2020-03-26 16:52:26 -07:00
Lars Lehtonen fa98a909fe lib/web: WebSuite.client() fix dropped test error 2020-03-26 16:52:26 -07:00
Forrest Marshall ea45118850 detect old cert format on startup 2020-03-05 10:30:20 -08:00
Forrest Marshall 56eea87d13 implement transparent UUID based routing 2020-03-05 10:30:20 -08:00
Russell Jones 94c2fd25d6 Added support for reexec during port forwarding.
Added support for reexec during port forwarding. This allows Teleport
nodes to run PAM code before port forwarding requests. This makes any
memory leaks in PAM code less dangerous as well as bringing port
forwarding logic in-line with execution requests (exec or shell).
2020-02-13 10:30:27 -08:00
Russell Jones 61ffec8f2d Don't call defer from function that exits.
Don't call os.Exit() from RunCommand() as any defers won't be called.
Instead wrap RunCommand() in RunAndExit() to allow defers to be called.
2020-02-06 11:15:44 -08:00
Russell Jones 77e8b63470 Enhanced Session Recording.
Added package cgroup to orchestrate cgroups. Only support for cgroup2
was added to utilize because cgroup2 cgroups have unique IDs that can be
used correlated with BPF events.

Added bpf package that contains three BPF programs: execsnoop,
opensnoop, and tcpconnect. The bpf package starts and stops these
programs as well  correlating their output with Teleport sessions
and emitting them to the audit log.

Added support for Teleport to re-exec itself before launching a shell.
This allows Teleport to start a child process, capture it's PID, place
the PID in a cgroup, and then continue to process. Once the process is
continued it can be tracked by it's cgroup ID.

Reduced the total number of connections to a host so Teleport does not
quickly exhaust all file descriptors. Exhausting all file descriptors
happens very quickly when disk events are emitted to the audit log which
are emitted at a very high rate.

Added tarballs for exec sessions. Updated session.start and session.end
events with additional metadata. Updated the format of session tarballs
to include enhanced events.

Added file configuration for enhanced session recording. Added code to
startup enhanced session recording and pass package to SSH nodes.
2019-12-02 15:10:39 -08:00
Alexander Klizhentas 8be98bcc21 Remove blacklisted FIPS ciphersuites, fix local_auth (#3103)
This commit fixes Web UI in FIPS mode when local_auth is false
and removes two ciphers banned by HTTP2 rfc spec:

https://tools.ietf.org/html/rfc7540#appendix-A

and used by FIPS, causing Teleport GRPC to fail.
2019-10-23 13:55:40 -07:00
Forrest Marshall 94808fdec1 fix web session ID generation 2019-09-17 13:19:03 -07:00
Russell Jones 9135a5ade7 Use roles and traits in certificate for RBAC.
If an attacker can force a username change at an IdP, upon second login,
the services.User object of the original user can be updated with new
roles and traits. If these new roles and traits differ, the original
user can have their privileges raised (or lowered).

To mitigate this, encode roles and traits within the certificate and use
these when fetching roles to make RBAC decisions. If roles and traits are
not encoded within an certificate (for example for old style SSH
certificates then fallback to using the services.User object and log a
warning.
2019-09-03 13:44:20 -07:00
Forrest Marshall 05f3eeaf00 Support resource-based bootstrapping for backend. (#2871)
* Support resource-based bootstrapping for backend.

Outside of static configuration, most of the persistent state of an
auth server exists as a collection of resources, stored in its
backend.  The resource API also forms the basis of Teleport's more
advanced dynamic configuration options.

This commit extends the usefulness of the resource API by adding
the ability to bootstrap backend state with a set of previously
exported resources.  This allows the resource API to serve as a
rudimentary backup/migration tool.

Notes: This features is a work in progress, and very easy to misuse;
while it will prevent you from overwriting the state of an existing
auth server, it won't stop you from bootstrapping into a wildly
misconfigured state.  In general, resource-based bootstrapping is
not a complete solution for backup or migration.

* update e-ref
2019-08-29 16:16:03 -07:00
Sasha Klizhentas aad397fbbd Better error message for IdP initated logins.
Fixes #2648

Teleport does not support SAML identity provider
initiated logins, this commit gives a better
error message to the user instructing them
what to do.
2019-08-06 16:40:29 -07:00
Alexey Kontsevoy 784f8f5f9c Do not clear cookies when bearer token does not match (#2854) 2019-07-12 09:53:33 -04:00
Alexander Klizhentas c9f8ac1791 Better errors for invalid OIDC connectors, fixes #2690 (#2827)
Invalid or inaccessible OIDC connectors were preventing
all other logins to work, as they were grabbing mutex
and making a network call.

Besides, the error was not informative as the user
saw "web headers timeout" error in the browser.

This fix makes sure that:

* Connector errors are isolated to the connector name
and other flows are not blocked
* Error is presented to user in a reasonable way and
provides instructions
* Administrator can see the error in the audit logs.
2019-07-10 10:27:42 -07:00
Alexey Kontsevoy 1544d4008e Add Tunnel indicator to IP Address cell (#2775)
* Add Tunnel indicator to IP Address cell

* E ref and dist

addesses #2751
2019-06-14 15:29:59 -04:00
Russell Jones 09241c635e Added support for FedRAMP/FIPS 140-2.
Added "--fips" flag to "teleport start" command which can start
Enterprise in FedRAMP/FIPS 140-2 mode.

In FIPS mode, Teleport configures the TLS and SSH servers with FIPS
compliant cryptographic algorithms. In FIPS mode, if non-compliant
algorithms are chosen, Teleport will fail to start. In addition,
Teleport checks if the binary was compiled against an approved
cryptographic module (BoringCrypto) and fails to start if it was not.
If a client, like tsh, tries to use non-FIPS encryption, like NaCl,
those requests are also rejected.
2019-05-07 12:51:02 -07:00
Sasha Klizhentas e3ca4df5fc Simplify IOT reverse tunnel logic.
In case of IOT (whenever teleport nodes are
connecting to the proxy), there is no need
to create ReverseTunnel objects in the backend,
as there is always one reverse tunnel per node.

This commit removes the logic that created
reverse tunnel object in the backed in IOT cases
and refactors some other parts of the code.
2019-05-03 10:51:06 -07:00
Sasha Klizhentas d5243dbe8d Add keep alive support to GRPC clients.
This commit turns on KeepAlive support
for GRPC clients to make sure that dropped
connections are detected properly.
2019-05-02 15:09:33 -07:00
Sasha Klizhentas 7467e47718 Cache auth servers and new find endpoint
Whenever many IOT style nodes are connecting
back to the web proxy server, they all
call /find endpoint to discover the configuration.

This new endpoint is designed to be fast and not
hit the database.

In addition to that every proxy reverse tunnel
connection handler was fetching auth servers and
this commit adds caching for the auth servers
on the proxy side.
2019-04-30 17:43:01 -07:00
Russell Jones 6d1c16f745 Added support for nodes dialing back to cluster.
Updated services.ReverseTunnel to support type (proxy or node). For
proxy types, which represent trusted cluster connections, when a
services.ReverseTunnel is created, it's created on the remote side with
name /reverseTunnels/example.com. For node types, services.ReverseTunnel
is created on the main side as /reverseTunnels/{nodeUUID}.clusterName.

Updated services.TunnelConn to support type (proxy or node). For proxy
types, which represent trusted cluster connections, tunnel connections
are created on the main side under
/tunnelConnections/remote.example.com/{proxyUUID}-remote.example.com.
For nodes, tunnel connections are created on the main side under
/tunnelConnections/example.com/{proxyUUID}-example.com. This allows
searching for tunnel connections by cluster then allows easily creating
a set of proxies that are missing matching services.TunnelConn.

The reverse tunnel server has been updated to handle heartbeats from
proxies as well as nodes. Proxy heartbeat behavior has not changed.
Heartbeats from nodes now add remote connections to the matching local
site. In addition, the reverse tunnel server now proxies connection to
the Auth Server for requests that are already authenticated (a second
authentication to the Auth Server is required).

For registration, nodes try and connect to the Auth Server to fetch host
credentials. Upon failure, nodes now try and fallback to fetching host
credentials from the web proxy.

To establish a connection to an Auth Server, nodes first try and connect
directly, and if the connection fails, fallback to obtaining a
connection to the Auth Server through the reverse tunnel. If a
connection is established directly, node startup behavior has not
changed. If a node establishes a connection through the reverse tunnel,
it creates an AgentPool that attempts to dial back to the cluster and
establish a reverse tunnel.

When nodes heartbeat, they also heartbeat if they are connected directly
to the cluster or through a reverse tunnel. For nodes that are connected
through a reverse tunnel, the proxy subsystem now directs the reverse
tunnel server to establish a connection through the reverse tunnel
instead of directly.

When sending discovery requests, the domain field has been replaced with
tunnelID. The tunnelID field is either the cluster name (same as before)
for proxies, or {nodeUUID}.example.com for nodes.
2019-04-26 15:41:45 -07:00
Roman Tkachenko 1828e21ef4 [Forward-port] Update audit events with additional fields. (#2655) 2019-04-17 10:16:28 -07:00
Sasha Klizhentas 8356ae6a74 Use in-memory cache for the auth server API.
This commit expands the usage of the caching layer
for auth server API:

* Introduces in-memory cache that is used to serve all
Auth server API requests. This is done to achieve scalability
on 10K+ node clusters, where each node fetches certificate authorities,
roles, users and join tokens. It is not possible to scale
DynamoDB backend or other backends on 10K reads per seconds
on a single shard or partition. The solution is to introduce
an in-memory cache of the backend state that is always used
for reads.

* In-memory cache has been expanded to support all resources
required by the auth server.

* Experimental `tctl top` command has been introduced to display
common single node metrics.

Replace SQLite Memory Backend with BTree

SQLite in memory backend was suffering from
high tail latencies under load (up to 8 seconds
in 99.9%-ile on load configurations).

This commit replaces the SQLite memory caching
backend with in-memory BTree backend that
brought down tail latencies to 2 seconds (99.9%-ile)
and brought overall performance improvement.
2019-04-12 14:23:09 -07:00
Roman Tkachenko e67bd2f31b Add 'search events' web API method. (#2637) 2019-04-05 11:35:19 -07:00
Russell Jones 2a6328dedc Replace NaCl with AES-GCM.
Added github.com/gravitational/teleport/lib/secret package to replace
github.com/mailgun/lemma to move from NaCl to AES-GCM. NaCl is still
supported for legacy clients.
2019-03-18 14:55:43 -07:00
Russell Jones ca81521966 Moved expires to resource metadata for services.Users.
Moved expiry field from spec to metadata for services.Users and updated
expiry check to prefer metadata and fallback to spec if not found. Added
test coverage.
2019-02-18 18:30:52 -08:00
Russell Jones ee4eba392e Use constant time compare to check bearer token. 2019-01-11 11:50:06 -08:00
Sasha Klizhentas f40df845db Events and GRPC API
This commit introduces several key changes to
Teleport backend and API infrastructure
in order to achieve scalability improvements
on 10K+ node deployments.

Events and plain keyspace
--------------------------

New backend interface supports events,
pagination and range queries
and moves away from buckets to
plain keyspace, what better aligns
with DynamoDB and Etcd featuring similar
interfaces.

All backend implementations are
exposing Events API, allowing
multiple subscribers to consume the same
event stream and avoid polling database.

Replacing BoltDB, Dir with SQLite
-------------------------------

BoltDB backend does not support
having two processes access the database at the
same time. This prevented Teleport
using BoltDB backend to be live reloaded.

SQLite supports reads/writes by multiple
processes and makes Dir backend obsolete
as SQLite is more efficient on larger collections,
supports transactions and can detect data
corruption.

Teleport automatically migrates data from
Bolt and Dir backends into SQLite.

GRPC API and protobuf resources
-------------------------------

GRPC API has been introduced for
the auth server. The auth server now serves both GRPC
and JSON-HTTP API on the same TLS socket and uses
the same client certificate authentication.

All future API methods should use GRPC and HTTP-JSON
API is considered obsolete.

In addition to that some resources like
Server and CertificateAuthority are now
generated from protobuf service specifications in
a way that is fully backward compatible with
original JSON spec and schema, so the same resource
can be encoded and decoded from JSON, YAML
and protobuf.

All models should be refactored
into new proto specification over time.

Streaming presence service
--------------------------

In order to cut bandwidth, nodes
are sending full updates only when changes
to labels or spec have occured, otherwise
new light-weight GRPC keep alive updates are sent
over to the presence service, reducing
bandwidth usage on multi-node deployments.

In addition to that nodes are no longer polling
auth server for certificate authority rotation
updates, instead they subscribe to event updates
to detect updates as soon as they happen.

This is a new API, so the errors are inevitable,
that's why polling is still done, but
on a way slower rate.
2018-12-10 17:20:24 -08:00
Russell Jones ccab010062 Advertise a minimum version for clients. 2018-11-16 16:34:19 -08:00
Alexey Kontsevoy de16c14429 webai - return sorted trusted clusters 2018-11-15 17:45:10 -05:00
Alexey Kontsevoy 90b98c678b do not close websocket connection on empty string (#2351) 2018-11-08 17:54:59 -05:00
Alexey Kontsevoy 2a5cbdf78b add buffer to terminal (#2325) 2018-10-31 10:44:10 -04:00
Russell Jones 217188ce64 Pass site name along in fileTransferRequest. 2018-10-29 10:29:06 -07:00
Russell Jones ec7e53370d Fix formatting issues. 2018-10-19 16:25:01 -07:00
Russell Jones 064038a6d3 Propagate cancelation context. 2018-10-12 17:42:37 -07:00
Sasha Klizhentas 02a33675ed Detect remote cluster by SNI name
This commit improves performance of teleport with
hundreds of connected trusted clusters.

TLS handshake protocol expects server to send a
list of trusted certificate authorities to the client
and client must present certificate signed by those.

With Teleport current implementation, every remote cluster
client is signed by local certificate and is not cross
signed.

Auth server now expects clients to announce the
remote cluster they are connecting from using SNI.

Auth server will send only certificate authorities
of the cluster announced via SNI.

Alternative idea is to cross sign the certificate
of the client of the remote cluster. We will explore
this idea in the next releases.

This commit also removes unnecessary reads
from the database to check the remote server status
that slows down user interface and other clients.

This is done at the expense of proxies showing
servers as offline in case if this individual
proxy does not have the connection, although
it's a small UI price to pay for not reading
the database, as proxy will eventually
get the connection thanks to the discovery
protocol.
2018-09-28 11:00:36 -07:00
Russell Jones 1439408b34 If the server has a public address set, use that as the address instead
of the one passed in by the user.
2018-08-31 16:33:54 -07:00
Russell Jones 3d9c34f1f0 Don't pass and clone client *tls.Config, instead pass cipher suites and
create new *tls.Config. Add test coverage for this.
2018-08-21 17:09:57 -07:00
Russell Jones 617b35128c Made GetNodes identity aware to only return nodes which that user has
access to. In debug mode, made RBAC failures more verbose.
2018-08-20 16:10:35 -07:00