Commit Graph
159 Commits
Author SHA1 Message Date
Carson Anderson e577b41244 Change client dialOpts append order (#11322)
* change order of dialOpts to respect config provided opts
2022-03-24 15:17:25 +00:00
Andrew Burke 4543bfd98d Respect HTTP_PROXY/HTTPS_PROXY (#10209)
This change allows tsh to use HTTP proxies when HTTP_PROXY/HTTPS_PROXY is set in the environment.
2022-03-23 19:58:19 +00:00
Alex McGrath 3d35263a6c Add a .tsh/config file and add support for configuring custom http headers 2022-03-23 14:19:07 +00:00
Zac Bergquist 3f507dfd06 Remove uses of deprecated ioutil package 2022-03-16 15:05:42 -06:00
Lisa Kim 350ea5bb95 Updates tsh ls for node/app/db/kube to accept new filter flags (#10980)
* Also adds a search keyword parser that takes in different
  delimiters (comma is used for tsh, space is used for web UI)

part of RFD 55
2022-03-09 23:56:55 +00:00
Lisa Kim b868ccce5f Add sorting for kube cluster (#10702)
Part of RFD 55
2022-03-07 09:54:58 -08:00
Lisa Kim 632d851783 Add KindWindowsDesktops to ListResources (#10769)
* Also add windows desktops sorter and its type converters
* Use forked vulcand/predicate library: allows traversing
  by embedded fields

Part of RFD 55
2022-03-07 08:58:26 -08:00
Alan Parra 5023235909 Add passwordless login/registration to auth and web (#10632)
Wire passwordless registration and authorization into Auth and Proxy APIs, thus
making passwordless logins possible.

API changes are described by RFD 52: Passwordless [1].

#9160

[1] https://github.com/gravitational/teleport/blob/master/rfd/0052-passwordless.md#authentication-api-changes

* Add passwordless settings to Auth protos
* Update generated protos
* Register: Apply DeviceUsage in lib/auth
* Register: Apply DeviceUsage in lib/web
* Login: Generate passwordless challenge
* Login: Allow passwordless authentication
* Wire passwordless in lib/web endpoints
* Make mocku2f passwordless setup a bit nicer
2022-03-04 18:41:35 +00:00
Nic Klaassen 6e16ad6627 IAM join method support for tbot (#10535) 2022-03-01 00:35:34 +00:00
Lisa Kim e7eb6c4af8 Return filtered total count with ListResources (#10573)
* The web UI needed to show the total count of resources available after filter
* ListResources response returns as a struct to make adding extra fields easier
2022-02-28 21:51:19 +00:00
Alan Parra bac0ccdc99 Remove U2F support (#10476)
Follows up on #10466 by removing remaining U2F references, including proto/gRPC
surface and the lib/auth/u2f package itself.

#10375

* Remove U2F from lib/auth/ (1)
* Remove U2F from lib/auth/ (2)
* Remove U2F from lib/auth/ (3)
* Remove U2F from lib/services/
* Remove U2F from tsh mfa add suggestions
* Remove U2F protos
* Update generated protos
* Cleanup a few stragglers
* Remove lib/auth/u2f package
* Fix references to auth.MFAAuthenticateChallenge
* Revert needless lib/auth/password.go change
* Update e/ to ad8fd4a (U2F cleanup)
* Fix stragglers from latest master rebase
* Fix lint and compile failures
2022-02-24 19:54:28 +00:00
bb121d7b1e Certificate renewal bot (#10099)
* Add certificate renewal bot

This adds a new `tbot` tool to continuously renew a set of
certificates after registering with a Teleport cluster using a
similar process to standard node joining.

This makes some modifications to user certificate generation to allow
for certificates that can be renewed beyond their original TTL, and
exposes new gRPC endpoints:
 * `CreateBotJoinToken` creates a join token for a bot user
 * `GenerateInitialRenewableUserCerts` exchanges a token for a set of
   certificates with a new `renewable` flag set

A new `tctl` command, `tctl bots add`, creates a bot user and calls
`CreateBotJoinToken` to issue a token. A bot instance can then be
started using a provided command.

* Cert bot refactoring pass

* Use role requests to split renewable certs from end-user certs
* Add bot configuration file
* Use `teleport.dev/bot` label
* Remove `impersonator` flag on initial bot certs
* Remove unnecessary `renew` package
* Misc other cleanup

* Do not pass through `renewable` flag when role requests are set

This adds additional restrictions on when a certificate's `renewable`
flag is carried over to a new certificate. In particular, it now also
denies the flag when either role requests are present, or the
`disallowReissue` flag has been previously set.

In practice `disallow-reissue` would have prevented any undesired
behavior but this improves consistency and resolves a TODO.

* Various tbot UX improvements; render SSH config

* Fully flesh out config template rendering
* Fix rendering for SSH configuration templates
* Added `String()` impls for destination types
* Improve certificate renewal logging; show more detail
* Properly fall back to default (all) roles
* Add mode hints for files
* Add/update copyright headers

* Add stubs for tbot init and watch commands

* Add gRPC endpoints for managing bots

* Add `CreateBot`, `DeleteBot`, and `GetBotUsers` gRPC endpoints
* Replace `tctl bot (add|rm|ls)` implementations with gRPC calls
* Define a few new constants, `DefaultBotJoinTTL`, `BotLabel`,
  `BotGenerationLabel`

* Fix outdated destination flag in example tbot command

* Bugfix pass for demo

* Fixed a few nil pointer derefs when using config from CLI args
* Properly create destination if `--destination-dir` flag is used
* Remove improper default on CLI flag
* `DestinationConfig` is now a list of pointers

* Address first wave of review feedback

Fixes the majority of smaller issues caught by reviewers, thanks all!

* Add doc comments for bot.go functions

* Return the token TTL from CreateBot

* Split initial user cert issuance from `generateUserCerts()`

Issuing initial renewable certificate ended up requiring a lot of
hacks to skip checks that prevented anonymous bots from getting
certs even though we'd verified their identity elsewhere (via token).

This reverts all those hacks and splits initial bot cert logic into a
dedicated `generateInitialRenewableUserCerts()` function which should
make the whole process much easier to follow.

* Set bot traits to silence log messages

* tbot log message consistency pass

* Resolve lints

* Add config tests

* Remove CreateBotJoinToken endpoint

Users should instead use the CreateBot/DeleteBot endpoints.

* Create a fresh private key for every impersonated identity renewal

* Hide `config` subcommand

* Rename bot label prefix to `teleport.internal/`

* Use types.NewRole() to create bot roles

* Clean up error handling in custom YAML unmarshallers

Also, add notes about the supported YAML shapes.

* Fetch proxy host via gRPC Ping() instead of GetProxies()

* Update lib/auth/bot.go

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* Fix some review comments

* Add renewable certificate generation checks (#10098)

* Add renewable certificate generation checks

This adds a new validation check for renewable certificates that
maintains a renewal counter as both a certificate extension and a
user label. This counter is used to ensure only a single certificate
lineage can exist: for example, if a renewable certificate is stolen,
only one copy of the certificate can be renewed as the generation
counter will not match

When renewing a certificate, first the generation counter presented
by the user (via their TLS identity) is compared to a value stored
with the associated user (in a new `teleport.dev/bot-generation`
label field). If they aren't equal, the renewal attempt fails.
Otherwise, the generation counter is incremented by 1, stored to the
database using a `CompareAndSwap()` to ensure atomicity, and set on
the generated certificate for use in future renewals.

* Add unit tests for the generation counter

This adds new unit tests to exercise the generation counter checks.

Additionally, it fixes two other renewable cert tests that were
failing.

* Remove certRequestGeneration() function

* Emit audit event when cert generations don't match

* Fully implement `tctl bots lock`

* Show bot name in `tctl bots ls`

* Lock bots when a cert generation mismatch is found

* Make CompareFailed respones from validateGenerationLabel() more actionable

* Update lib/services/local/users.go

Co-authored-by: Nic Klaassen <nic@goteleport.com>

* Backend changes for tbot IoT and AWS joining (#10360)

* backend changes

* add token permission check

* pass ctx from caller

Co-authored-by: Roman Tkachenko <roman@goteleport.com>

* fix comment typo

Co-authored-by: Roman Tkachenko <roman@goteleport.com>

* use UserMetadata instead of Identity in RenewableCertificateGenerationMismatch event

* Client changes for tbot IoT joining (#10397)

* client changes

* delete replaced APIs

* delete unused tbot/auth.go

* add license header

* don't unecessarily fetch host CA

* log fixes

* s/tunnelling/tunneling/

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* auth server addresses may be proxies

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* comment typo fix

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* move *Server methods out of auth_with_roles.go (#10416)

Co-authored-by: Tim Buckley <tim@goteleport.com>

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>
Co-authored-by: Tim Buckley <tim@goteleport.com>

Co-authored-by: Roman Tkachenko <roman@goteleport.com>
Co-authored-by: Tim Buckley <tim@goteleport.com>
Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

Co-authored-by: Nic Klaassen <nic@goteleport.com>
Co-authored-by: Roman Tkachenko <roman@goteleport.com>
Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* Address another batch of review feedback

* Addres another batch of review feedback

Add `Role.SetMetadata()`, simplify more `trace.WrapWithMessage()`
calls, clear some TODOs and lints, and address other misc feedback
items.

* Fix lint

* Add missing doc comments to SaveIdentity / LoadIdentity

* Remove pam tag from tbot build

* Update note about bot lock deletion

* Another pass of review feedback

Ensure all requestable roles exist when creating a bot, adjust the
default renewable cert TTL down to 1 hour, and check types during
`CompareAndSwapUser()`

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>
Co-authored-by: Nic Klaassen <nic@goteleport.com>
Co-authored-by: Roman Tkachenko <roman@goteleport.com>
2022-02-19 02:41:45 +00:00
Marek Smoliński 28907e17a0 Add MFA for Windows Desktop web access (#10271) 2022-02-18 22:01:46 +00:00
Lisa Kim e82450b8ed Add missing action VerbRead to ListResources (#10422) 2022-02-18 20:51:37 +00:00
Alex McGrathandZac Bergquist 611c05106f Add support for windows desktop services proxying different desktops (#10101)
* Add support for windows desktop services proxying different desktops

* Add filter to GetWindowsDesktops, remove GetWindowsDesktop and GetWindowsDesktopByName

* Cache cleanup

* Fix cache deletes for Windows desktops

For deletes, the cache only gets the backend key, not the entire
resource. Do what database access does, which is to extract the
host ID from the path, and stuff it in the description field of
the resource header.

* Godoc cleanup

* Fix lint

* Address review comments

* Send error message if no desktop found

* Revert to x/net/websocket

This got converted to gorilla/websocket as part of moderated sessions.
We'll do a more intentional conversion post-release.

* fix lint

Co-authored-by: Zac Bergquist <zac.bergquist@goteleport.com>
2022-02-18 00:01:08 +00:00
Andrew Burke 4e3bd6c647 Clear terminal when auth server is in FIPS mode (#10095)
This change clears the terminal at the end of a session when the auth server is in FIPS mode, even if tsh isn't.
2022-02-17 10:16:36 -08:00
Lisa Kim 74a21212c3 Implement resource sorter for server, appserver, dbserver (#10243)
* Define sorters for resource Server, AppServer, and DbServer
* Add sorting to ListResources in caching and presence layer
* ListResources now returns nextKey set to the limit+1th item,
  previously it returned a possible next key, where there
  may or may not be more results.
2022-02-17 00:42:03 +00:00
Joel ea810d30d9 Implement Moderated Sessions (#8563)
* Implement Moderated Sessions
2022-02-15 17:02:10 +01:00
Carson Anderson cc1e13154c Add keepalive heartbeat to kubernetes service (#9584)
This adds an rpc UpsertKubeServiceV2 to replace UpsertKubeService. Currently, kubernetes service does not have a keepalive heartbeat unlike app, db, and windows service. This brings functionality in line with the others. This would allow for future use of the keepalive to track connected agents via prometheus metrics.
2022-02-10 14:54:03 -07:00
Nic Klaassen 37d108ce14 commit forgotten "make grpc" (#10280) 2022-02-10 21:09:40 +00:00
Nic Klaassen bc441ef2cf IAM Join Method (gRPC service) (#10087) 2022-02-10 00:41:34 +00:00
Lisa Kim ab392ef4f6 Add additional filters to ListResources (#10180)
Takes resource parser and match search and 
adds these filters to ListResources.
Allows resource filtering by labels, search keywords, 
or with the predicate language.

Part of RFD 55
2022-02-07 13:12:30 -08:00
Marek Smoliński fbd5a2aafd Fix tsh tctl do not load all CAS (#9357) 2022-01-31 13:35:15 +01:00
Gabriel Corado e426b782a9 feat: add KubeService and Node to ListResources (#9613) 2022-01-25 15:48:13 +00:00
Edoardo Spadolini e254076700 Improved Google OIDC connector (#9697)
* go get google.golang.org/api

go get: upgraded cloud.google.com/go v0.60.0 => v0.100.2
go get: upgraded github.com/golang/snappy v0.0.1 => v0.0.3
go get: upgraded github.com/googleapis/gax-go/v2 v2.0.5 => v2.1.1
go get: upgraded go.opencensus.io v0.22.5 => v0.23.0
go get: upgraded golang.org/x/oauth2 v0.0.0-20200107190931-bf48bf16ab8d => v0.0.0-20211104180415-d3ed0bb246c8
go get: upgraded google.golang.org/api v0.29.0 => v0.65.0

* Optionally fetch transitive groups in the Google OIDC connector

* Refactor the google workspace parts of the OIDC code

* Further refactoring

This undoes the user account impersonation changes, and always requires
an admin account again.

* Test coverage

* Address review comments

* Minor refactor and name changes

* Allow domain filtering, tests now bypass addGoogleWorkspaceClaims

* Update `OIDCConnectorV2` to `OIDCConnectorV3`

* Backwards compatibility for OIDCConnector v2

This also removes the extra boolean flag that was added previously.

* Update e-ref

Enterprise builds will break unless gravitational/teleport.e#385
is included.
2022-01-21 18:26:28 +00:00
Tim Buckleyandrosstimothy 6d2ab51d0d Allow impersonation of roles without users (#9561)
* Allow impersonation of roles without users

This adds the ability to impersonate one or more roles without
impersonating a particular user.

In Teleport today, when creating an impersonator role, both users and
roles must be specified as impersonation is fundamentally tied to an
existing Teleport user:
```yaml
allow:
  impersonate:
    users: ['jenkins']
    roles: ['jenkins']
```

This is inconvenient for two reasons:
 1. A user must exist for each set of roles you'd like to
    impersonate, creating a UX burden.
 2. It makes it difficult to use impersonation to reduce one's
    permissions as you always inherit all of the roles granted to the
    target user.

For the [certificate bot][bot] we'd instead like to use impersonation
to generate end-user (impersonated) certificates with a reduced set
of permissions. For example, given the following role:
```yaml
allow:
  impersonate:
    roles: ['jenkins', 'deploy']
```

We can then use `GenerateUserCerts` to issue certifices for a subset
of the allowed roles, e.g. one set of certificates with only the
`jenkins` role attached, and another with only `deploy`.

To that end, this patch:
 1. Removes the requirement that roles define both `users` and
    `roles` in impersonate conditions
 2. Introduces a new `RoleRequests` field in `UserCertsRequest`
 3. Modifies `generateUserCerts` to gather `roles` from
    `RoleRequests` if allowed by an `allow` (with no `users`)

[bot]: https://github.com/gravitational/teleport/pull/7986

* Add `determineDesiredRolesAndTraits`; audit log on role impersonation

This splits initial role and trait determination into a new function,
`determineDesiredRolesAndTraits`, to improve control flow and clarity
given the new branches introduced for role impersonation.

Additionally, this moves the call to `CheckRoleImpersonation` down
to match regular user impersonation's flow, and emits an audit log
event on failure.

* Formatting fix

* Unit testing for role requests

This adds a new set of unit tests for role requests.

Also discovered the `impersonator` field wasn't being set for
role impersonation, so it's now set to the user's own username.
In other words, role impersonation will appear (in the audit log and
elsewhere) as self-impersonation.

* Clean up testing users between runs

* Deny most reimpersonation cases and add tests

This attempts to deny most cases of reimpersonation, where an
impersonated certificate might be used to generate certificates for
other roles the user is allowed to impersonate.

One test case is currently failing pending a solution.

* Add new DisallowReissue certificate extension

This adds a new DisallowReissue certificate extension that, if set,
prevents that identity from interacting with `GenerateUserCerts`.

This flag is always set when RoleRequests are used to prevent
unintended privilege escalation (while avoiding breaking changes to
Teleport's existing certificate generation behavior).

* Fix test lints

* Fix typo

* Fix test doc typo, add testcase for user impersonation misuse

* Apply suggestions from code review

Co-authored-by: rosstimothy <39066650+rosstimothy@users.noreply.github.com>

* Accept context in CreateRole per review feedback

* Fix misleading comment

Co-authored-by: rosstimothy <39066650+rosstimothy@users.noreply.github.com>
2022-01-14 15:15:13 -07:00
Isaiah Becker-MayerandZac Bergquist 575da9e3de Fix first desktop discovery reconcile loop (#9654)
* Adds logic for grabbing known desktops from the auth server when the desktop discovery's reconciler starts up

* moving desktop initialization into goroutine

* Apply suggestions from code review

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* minor fixes

* removes initial discovery logic since it would break a multi-w_d_s setup, instead solves the problem by changing discovery's create function to an upsert

* consolidating verb check call

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>
2022-01-14 21:29:57 +00:00
rosstimothy 95d0f0d27f Update google.golang.org/grpc to v1.43.0 (#9656)
Update grpc dependency to the latest version. Needed to fix the client side hang that
prevents TwoClustersTunnel from running succesfully, see #9655.
2022-01-10 15:36:50 -05:00
Isaiah Becker-Mayer bc11f2dfe6 Adds Desktops to license (#9576)
* Adds Desktops to license

* adds newline
2022-01-06 18:43:47 +00:00
Marek Smoliński 5afd0e6204 Update API client: dial auth service with TLS Routing (#9498) 2022-01-03 11:32:45 +01:00
Gabriel Corado 5f403562ab feat: ListResources gRPC rpc (#9096) 2021-12-15 18:09:21 +00:00
Marek Smoliński f906831e58 Add ability to run Mongo proxy on separate listener (#9194) 2021-12-14 14:26:14 +01:00
Marek Smoliński d24ae5b1ce Add ability to run Postgres proxy on separate listener (#8323) 2021-12-10 11:05:19 +01:00
Zac Bergquist 53562aadb0 Use t.Setenv in tests (#9154)
This new feature in Go 1.17 automatically restores the environment
variable to its previous value when a test ends, making it simpler
to set up the environment for tests and less likely that we accidentally
leave behind global state.

Also convert some of the remaining uses of check to standard Go tests.
2021-12-01 10:43:12 -07:00
Brian Joerger 6512bca599 Move unimplemented client methods out of the api client. (#8972) 2021-11-17 15:42:44 -08:00
Brian JoergerandZac Bergquist 664560cee8 teleport.cluster.local cleanup (#7922)
Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>
2021-11-15 17:32:45 -08:00
Marek Smoliński 33f8a021b1 Fix tunnel address for TLS routing if public tunnel address is present (#8961) 2021-11-15 12:58:22 -08:00
Trent Clarke 3956ed27a6 Fix race condition in integration tests. (#8888)
Some integration tests modify global "constants" to speed up test
execution (e.g. shortening polling intervals). This is occasionally
tripping the Go data race detector, so I have added explicit
serialisation to reading and writing these global settings.

These values are only ever changed in a test environment, and there
should be zero contention for them in a non-test environment.
2021-11-10 11:34:34 +11:00
Lisa Kim c5b2da13b7 Return created date with new recovery codes (#8777) 2021-10-29 20:14:56 -07:00
Forrest Marshall 7f39084def fix nits 2021-10-22 16:42:33 -07:00
Forrest Marshall 19c5768873 server-side filtering 2021-10-22 16:42:33 -07:00
Marek Smoliński 17a5cadabb Add Proxy listener mode and proxy v2 configuration (#8511) 2021-10-21 14:45:47 +02:00
rosstimothy c730778960 Replace golint with revive (#8613) 2021-10-19 14:00:24 -04:00
Marek Smoliński 7606d330e9 AWS CLI access (#8151) 2021-10-19 10:43:53 +02:00
Andrej Tokarčík b86fa7bfa8 Implement where conditions for session recordings list/read (#8289) 2021-10-08 10:18:22 -07:00
Roman Tkachenko 288c5519ce Accept multiple SANs in tctl auth sign for databases (#8449) 2021-10-05 16:00:28 -07:00
Andrew Lytvynov 813dff20c1 PIV authentication for RDP (#8408)
* PIV authentication for RDP

This uncomfortably large change fully implements smartcard PIV
authentication for RDP clients using the Teleport CA:
- PIV applet implementation in emulated RDP smartcard
- generating Windows-compatible certificates using Teleport CA with a
  dedicated RPC
- generating dummy CRLs for Teleport CA and publishing it via LDAP

The CRLs are required by Windows for any smartcard login certificate, we
can't avoid that. But we can avoid making it public: the CRL can live in
ActiveDirectory instead of a public endpoint of a Teleport service.
Here, we use LDAP to publish the CRL on startup, valid for a year.

There are a few unhandled cases in the current implementation:
- LDAP server certificate is not validated when upgrading to TLS
- multiple active CAs (with HSMs) are not supported, only one CRL is
  published
- CA rotation is not supported, CRL is not re-published on rotation

All of the above issues will be handled in future PRs as this one is
already too large.

* Address review feedback

* Fix linter errors
2021-10-01 15:01:17 -07:00
Alan Parra 93a7a8926b Return preferred MFA method on ping endpoints (#8439)
Give Teleport clients a consistent hint of which MFA method they should
favor when facing multiple options.

To be used by tsh and Web UI to decide whether they should refer to
"U2F" or "WebAuthn" during the transitional period.

* Return preferred MFA method on ping endpoints
2021-10-01 13:35:22 -07:00
Lisa Kim d0c09338ac Rename VerifyAccountRecovery and token ID proto fields (#8395)
- Rename ApproveAccountRecovery to VerifyAccountRecovery 
   to match the language we use for the UI
- Use generic TokenID field naming for requests where more 
   than one type of token is accepted or a single token use 
   may be unlikely (MFA related rpcs)
2021-09-28 10:29:11 -07:00
Nic Klaassen 99cc8eb5ef Require enterprise license for HSM support (#8370) 2021-09-27 10:40:47 -07:00