Commit Graph
215 Commits
Author SHA1 Message Date
STeve (Xin) Huang fd12e934ee RDS & Redshfit support for AWS China regions (part 1?) (#10560) 2022-03-25 17:40:51 +00:00
Alex McGrath 40200e8536 Reslove comments, move all occurences of teleport.dev to use a constant 2022-03-15 13:22:45 +00:00
Alex McGrath 19270c1e71 Resolve comments 2022-03-15 13:22:45 +00:00
Alex McGrath ad41b3c154 Move 'MakeTableWithTruncatedColumn' to asciitable and truncate labels 2022-03-15 13:22:45 +00:00
Alex McGrath cdae4e3ee2 ls consistency: add support for tctl desktop ls
```
Host Public Address       AD Domain   Labels               Version
---- -------------------- ----------- -------------------- ---------
corn 192.168.122.144:3389 example.com teleport..3 (9       9.0.0-dev
corn 192.168.122.51:3389  example.com teleport.rd Evle.com 9.0.0-dev
```

```yaml
kind: windows_desktop
metadata:
  expires: "2022-02-18T16:12:52.422659238Z"
  id: 1645200172423989197
  labels:
    teleport.dev/computer_name: WIN-LA2V0OD7SK0
    teleport.dev/dns_host_name: WIN-LA2V0OD7SK0.example.com
    teleport.dev/is_domain_controller: "true"
    teleport.dev/origin: dynamic
    teleport.dev/os: Windows Server 2012 R2 Standard Evaluation
    teleport.dev/os_version: 6.3 (9600)
    teleport.dev/windows_domain: example.com
  name: WIN-LA2V0OD7SK0-example-com
spec:
  addr: 192.168.122.51:3389
  domain: example.com
  host_id: 2c807641-92ae-4c70-88fe-b93e7b0aa179
version: v3
```
2022-03-15 13:22:45 +00:00
Krzysztof SkrzętnickiandAlan Parra 0e5e9bf036 Fix quadratic complexity in Reconciler.Reconcile(). (#10989)
* Fix quadratic Reconciler.Reconcile() complexity.

Co-authored-by: Alan Parra <alan.parra@goteleport.com>
2022-03-10 12:06:56 +01:00
Brian Joerger 600022b290 Change NewRole to use V5 by default, old consumers now user NewRoleV3. (#10884) 2022-03-08 21:11:53 +00:00
Lisa Kim b868ccce5f Add sorting for kube cluster (#10702)
Part of RFD 55
2022-03-07 09:54:58 -08:00
Lisa Kim 632d851783 Add KindWindowsDesktops to ListResources (#10769)
* Also add windows desktops sorter and its type converters
* Use forked vulcand/predicate library: allows traversing
  by embedded fields

Part of RFD 55
2022-03-07 08:58:26 -08:00
Zac Bergquist 8ef9455fc7 Fix Windows session uploads
Ensure that the logic which checks for (and emits) a session.end
event also applies for windows.desktop.session.end events.

For this to work, we use the StreamSessionEvents API instead of
GetEvents. This is because the streaming API works for any stream
of audit events, and GetSessionEvents is specific to SSH and the
chunks index format used by SSH sessions.

Lastly, ensure that desktop related events are also captured in the
session recording stream (but omitted when streaming the events to
the browser during session playback). This allows us to use the
start event in order to reconstruct a missing end event.
2022-03-03 08:26:44 -07:00
Joel cda00f3e79 Add unknown event instead of error on audit log read (#10665) 2022-03-02 19:47:08 +00:00
Lisa Kim e7eb6c4af8 Return filtered total count with ListResources (#10573)
* The web UI needed to show the total count of resources available after filter
* ListResources response returns as a struct to make adding extra fields easier
2022-02-28 21:51:19 +00:00
Alan Parra bac0ccdc99 Remove U2F support (#10476)
Follows up on #10466 by removing remaining U2F references, including proto/gRPC
surface and the lib/auth/u2f package itself.

#10375

* Remove U2F from lib/auth/ (1)
* Remove U2F from lib/auth/ (2)
* Remove U2F from lib/auth/ (3)
* Remove U2F from lib/services/
* Remove U2F from tsh mfa add suggestions
* Remove U2F protos
* Update generated protos
* Cleanup a few stragglers
* Remove lib/auth/u2f package
* Fix references to auth.MFAAuthenticateChallenge
* Revert needless lib/auth/password.go change
* Update e/ to ad8fd4a (U2F cleanup)
* Fix stragglers from latest master rebase
* Fix lint and compile failures
2022-02-24 19:54:28 +00:00
Alan Parra f8b7b330ad Alias "u2f" to "webauthn" and partially cleanup (#10466)
Alias the "u2f" second factor mode to "webauthn", effectively sunsetting U2F in
favor of WebAuthn.

The change effectively disables "U2F mode" server-side, making Teleport use
WebAuthn instead. This is in line with our compatibility promise, as Teleport
8.x clients are already WebAuthn-capable (and thus have no problems talking to
the cluster).

I have cleaned up a good chunk of U2F references in lib/web and lib/client, plus
a few other places. Changes on lib/auth are just the necessary to get the tests
back to good standing. There is more work to be done, but this seems enough for
a single PR.

#10375

* Remove "Disabled" field from types.Webauthn
* Update generated protos
* Treat second_factor "u2f" as "webauthn"
* Remove references to Webauthn.Disabled
* Remove U2F from lib/web/
* Remove U2F from lib/client/
* Remove U2F from lib/auth/ (partially)
* Fix issues after rebase on master
* Fix typo
2022-02-23 14:10:13 +00:00
bb121d7b1e Certificate renewal bot (#10099)
* Add certificate renewal bot

This adds a new `tbot` tool to continuously renew a set of
certificates after registering with a Teleport cluster using a
similar process to standard node joining.

This makes some modifications to user certificate generation to allow
for certificates that can be renewed beyond their original TTL, and
exposes new gRPC endpoints:
 * `CreateBotJoinToken` creates a join token for a bot user
 * `GenerateInitialRenewableUserCerts` exchanges a token for a set of
   certificates with a new `renewable` flag set

A new `tctl` command, `tctl bots add`, creates a bot user and calls
`CreateBotJoinToken` to issue a token. A bot instance can then be
started using a provided command.

* Cert bot refactoring pass

* Use role requests to split renewable certs from end-user certs
* Add bot configuration file
* Use `teleport.dev/bot` label
* Remove `impersonator` flag on initial bot certs
* Remove unnecessary `renew` package
* Misc other cleanup

* Do not pass through `renewable` flag when role requests are set

This adds additional restrictions on when a certificate's `renewable`
flag is carried over to a new certificate. In particular, it now also
denies the flag when either role requests are present, or the
`disallowReissue` flag has been previously set.

In practice `disallow-reissue` would have prevented any undesired
behavior but this improves consistency and resolves a TODO.

* Various tbot UX improvements; render SSH config

* Fully flesh out config template rendering
* Fix rendering for SSH configuration templates
* Added `String()` impls for destination types
* Improve certificate renewal logging; show more detail
* Properly fall back to default (all) roles
* Add mode hints for files
* Add/update copyright headers

* Add stubs for tbot init and watch commands

* Add gRPC endpoints for managing bots

* Add `CreateBot`, `DeleteBot`, and `GetBotUsers` gRPC endpoints
* Replace `tctl bot (add|rm|ls)` implementations with gRPC calls
* Define a few new constants, `DefaultBotJoinTTL`, `BotLabel`,
  `BotGenerationLabel`

* Fix outdated destination flag in example tbot command

* Bugfix pass for demo

* Fixed a few nil pointer derefs when using config from CLI args
* Properly create destination if `--destination-dir` flag is used
* Remove improper default on CLI flag
* `DestinationConfig` is now a list of pointers

* Address first wave of review feedback

Fixes the majority of smaller issues caught by reviewers, thanks all!

* Add doc comments for bot.go functions

* Return the token TTL from CreateBot

* Split initial user cert issuance from `generateUserCerts()`

Issuing initial renewable certificate ended up requiring a lot of
hacks to skip checks that prevented anonymous bots from getting
certs even though we'd verified their identity elsewhere (via token).

This reverts all those hacks and splits initial bot cert logic into a
dedicated `generateInitialRenewableUserCerts()` function which should
make the whole process much easier to follow.

* Set bot traits to silence log messages

* tbot log message consistency pass

* Resolve lints

* Add config tests

* Remove CreateBotJoinToken endpoint

Users should instead use the CreateBot/DeleteBot endpoints.

* Create a fresh private key for every impersonated identity renewal

* Hide `config` subcommand

* Rename bot label prefix to `teleport.internal/`

* Use types.NewRole() to create bot roles

* Clean up error handling in custom YAML unmarshallers

Also, add notes about the supported YAML shapes.

* Fetch proxy host via gRPC Ping() instead of GetProxies()

* Update lib/auth/bot.go

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* Fix some review comments

* Add renewable certificate generation checks (#10098)

* Add renewable certificate generation checks

This adds a new validation check for renewable certificates that
maintains a renewal counter as both a certificate extension and a
user label. This counter is used to ensure only a single certificate
lineage can exist: for example, if a renewable certificate is stolen,
only one copy of the certificate can be renewed as the generation
counter will not match

When renewing a certificate, first the generation counter presented
by the user (via their TLS identity) is compared to a value stored
with the associated user (in a new `teleport.dev/bot-generation`
label field). If they aren't equal, the renewal attempt fails.
Otherwise, the generation counter is incremented by 1, stored to the
database using a `CompareAndSwap()` to ensure atomicity, and set on
the generated certificate for use in future renewals.

* Add unit tests for the generation counter

This adds new unit tests to exercise the generation counter checks.

Additionally, it fixes two other renewable cert tests that were
failing.

* Remove certRequestGeneration() function

* Emit audit event when cert generations don't match

* Fully implement `tctl bots lock`

* Show bot name in `tctl bots ls`

* Lock bots when a cert generation mismatch is found

* Make CompareFailed respones from validateGenerationLabel() more actionable

* Update lib/services/local/users.go

Co-authored-by: Nic Klaassen <nic@goteleport.com>

* Backend changes for tbot IoT and AWS joining (#10360)

* backend changes

* add token permission check

* pass ctx from caller

Co-authored-by: Roman Tkachenko <roman@goteleport.com>

* fix comment typo

Co-authored-by: Roman Tkachenko <roman@goteleport.com>

* use UserMetadata instead of Identity in RenewableCertificateGenerationMismatch event

* Client changes for tbot IoT joining (#10397)

* client changes

* delete replaced APIs

* delete unused tbot/auth.go

* add license header

* don't unecessarily fetch host CA

* log fixes

* s/tunnelling/tunneling/

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* auth server addresses may be proxies

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* comment typo fix

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* move *Server methods out of auth_with_roles.go (#10416)

Co-authored-by: Tim Buckley <tim@goteleport.com>

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>
Co-authored-by: Tim Buckley <tim@goteleport.com>

Co-authored-by: Roman Tkachenko <roman@goteleport.com>
Co-authored-by: Tim Buckley <tim@goteleport.com>
Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

Co-authored-by: Nic Klaassen <nic@goteleport.com>
Co-authored-by: Roman Tkachenko <roman@goteleport.com>
Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* Address another batch of review feedback

* Addres another batch of review feedback

Add `Role.SetMetadata()`, simplify more `trace.WrapWithMessage()`
calls, clear some TODOs and lints, and address other misc feedback
items.

* Fix lint

* Add missing doc comments to SaveIdentity / LoadIdentity

* Remove pam tag from tbot build

* Update note about bot lock deletion

* Another pass of review feedback

Ensure all requestable roles exist when creating a bot, adjust the
default renewable cert TTL down to 1 hour, and check types during
`CompareAndSwapUser()`

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>
Co-authored-by: Nic Klaassen <nic@goteleport.com>
Co-authored-by: Roman Tkachenko <roman@goteleport.com>
2022-02-19 02:41:45 +00:00
Edoardo Spadolini 6033148096 CertAuthority watcher filtering (#10020) 2022-02-19 00:48:16 +00:00
Gabriel Corado df44457b02 feat: aws database configurator (#9145) 2022-02-18 21:15:54 +00:00
Alex McGrathandZac Bergquist 611c05106f Add support for windows desktop services proxying different desktops (#10101)
* Add support for windows desktop services proxying different desktops

* Add filter to GetWindowsDesktops, remove GetWindowsDesktop and GetWindowsDesktopByName

* Cache cleanup

* Fix cache deletes for Windows desktops

For deletes, the cache only gets the backend key, not the entire
resource. Do what database access does, which is to extract the
host ID from the path, and stuff it in the description field of
the resource header.

* Godoc cleanup

* Fix lint

* Address review comments

* Send error message if no desktop found

* Revert to x/net/websocket

This got converted to gorilla/websocket as part of moderated sessions.
We'll do a more intentional conversion post-release.

* fix lint

Co-authored-by: Zac Bergquist <zac.bergquist@goteleport.com>
2022-02-18 00:01:08 +00:00
Alex McGrath 0abe3be6ee Add support for configurable ssh key extensions 2022-02-17 13:44:57 +00:00
Roman Tkachenko 41899806fd Add SQL Server support for database access (#10097) 2022-02-17 02:20:33 +00:00
Lisa Kim 74a21212c3 Implement resource sorter for server, appserver, dbserver (#10243)
* Define sorters for resource Server, AppServer, and DbServer
* Add sorting to ListResources in caching and presence layer
* ListResources now returns nextKey set to the limit+1th item,
  previously it returned a possible next key, where there
  may or may not be more results.
2022-02-17 00:42:03 +00:00
STeve (Xin) Huang 55fbd56217 MySQL prepared statement support (#10283) 2022-02-16 19:46:54 +00:00
Zac Bergquist adf03959b8 Add audit events for desktop clipboard access
Introduce two new audit events:

- desktop.clipboard.send: emitted when a user's local clipboard
  data is sent to teleport
- desktop.clipboard.receive: emitted when clipboard data is received
  from a remote windows desktop

Closes #9706
2022-02-16 10:53:13 -07:00
Joel ea810d30d9 Implement Moderated Sessions (#8563)
* Implement Moderated Sessions
2022-02-15 17:02:10 +01:00
Alan Parra beb2213ee7 Add passwordless-related information to protos (#10281)
Introduces webauthn.User (for usernameless logins) and extends
webauthn.SessionData and types.WebauthnDevice with relevant fields.

#9160

* Add passwordless-related information to protos
* Add missing field tags
* Update generated protos
* Reformat protos (make grpc)
2022-02-14 17:26:06 +00:00
c84b7f8142 Desktop session recording/playback (#9583)
* Record desktop sessions

Here we introduce a new protobuf type (DesktopRecording) that contains
an encoded TDP message, and update AuditWriter to treat these similarly
to SessionPrint events (which are used for SSH session recordings).

We also add desktop session playback endpoint, temporarily located at
/webapi/sites/:site/desktopplaybacktest/:session
which streams TDP messages from a recorded session over
a websocket interface.

* update session end (#9795)

* Updates SessionEnd event with fields needed for frontend

* removes the clock which didn't need to be passed

* Add `Recorded` field to `WindowsDesktopSessionEnd` (#9839)

* Adds the SessionRecording field to WindowsDesktopSessionEnd event to mimic SessionEnd events (useful for easy integration with frontend).

* 14 should have been 12

* removing test logic

* switches SessionRecording to simple boolean Recorded

* session recording websocket (#9908)

* Adds the SessionRecording field to WindowsDesktopSessionEnd event to mimic SessionEnd events (useful for easy integration with frontend).

* 14 should have been 12

* removing test logic

* switches SessionRecording to simple boolean Recorded

* Updates the websocket address

* updates desktopPlaybackHandle to restart playback once it reaches the end

* adds playback state and synchronization logic for ensuring that goroutines aren't leaked

* adds toggle functionality for play/pause

* fix for the fact that urls are case insensitive

* moves desktop_playback to its own file, fixes mistaken comment about how websocket.JSON.Receive works, fixes error messaging, wraps playbackState.Close in a sync.Once

* Adds a cond variable for the two goroutines, but doesn't solve the spinning loop problem for the hanging logic

* Adds a cancel-able context which is cancelled in ps.Close() in order to avoid a spinning loop in the websocket.Handler

* Moves the majority of playback logic into the playbackState, which is now renamed to the more accurate playbackPlayer.

* changes pp.hangWhilePaused to pp.waitWhilePaused

* Moves the context out of NewPlaybackPlayer and the playbackPlayer
struct, wraps playback goroutines in playbackPlayer.Play(ctx) in
order to comply with context semantics.

* removing unnecessary warnings

* touchups

* record screen size (#9992)

* Adds the SessionRecording field to WindowsDesktopSessionEnd event to mimic SessionEnd events (useful for easy integration with frontend).

* 14 should have been 12

* removing test logic

* switches SessionRecording to simple boolean Recorded

* Updates the websocket address

* updates desktopPlaybackHandle to restart playback once it reaches the end

* adds playback state and synchronization logic for ensuring that goroutines aren't leaked

* adds toggle functionality for play/pause

* fix for the fact that urls are case insensitive

* moves desktop_playback to its own file, fixes mistaken comment about how websocket.JSON.Receive works, fixes error messaging, wraps playbackState.Close in a sync.Once

* Adds a cond variable for the two goroutines, but doesn't solve the spinning loop problem for the hanging logic

* Adds a cancel-able context which is cancelled in ps.Close() in order to avoid a spinning loop in the websocket.Handler

* Moves the majority of playback logic into the playbackState, which is now renamed to the more accurate playbackPlayer.

* changes pp.hangWhilePaused to pp.waitWhilePaused

* Moves the context out of NewPlaybackPlayer and the playbackPlayer
struct, wraps playback goroutines in playbackPlayer.Play(ctx) in
order to comply with context semantics.

* removing unnecessary warnings

* Adds an OnRecv that's similar to OnSend, for emitting audit events for particular incoming tdp messages

* Send full `DesktopRecording` event as json over playback websocket. (#10052)

* playback websocket now sends a json representation of the DesktopRecording event rather than just the raw tdp message, in order for us to have timing data on the frontend

* updating json.Marshal to utils.FastMarshal

* Removing unnecessary comment

* playback end event (#10088)

* Adds an end event so that the playback player knows to set the progress bar to its end state

* making the end message a json

* if the marshal fails we don't want to send a message over websocket

* Use a static string

Co-authored-by: Edoardo Spadolini <edoardo.spadolini@goteleport.com>

Co-authored-by: Edoardo Spadolini <edoardo.spadolini@goteleport.com>

* Add participants to session end event

Desktop sessions are not joinable, so the participants list always
has a single member - the user who started the session.

This will ensure that our example role for RBAC for sessions
(which depends on the participants field) will work for desktop
sessions.

* Minor cleanup

* Only record sessions when enabled

In order for desktop sessions to be recorded, session recording
must be enabled in the cluster's session recording config and
at least one of the user's roles must enable it.

* Cleanup

* Start to address review comments

* Move TDP event handlers out of connectRDP

* Address more review comments and add some tests

* Add playback streaming test

* Consistent comments

* Fix tests

* Don't log PNG frames that exceed the size of a protobuf

Since the PNG frame message in our desktop protocol is unbounded,
it is theoretically possible for a message to exceed the size limit
of a single protobuf.

In practice, this is unlikely to occur with any legitimate RDP traffic,
as the bitmaps are at most 64x64 pixels and compressed in PNG form.
Rather than complicating the protocol to allow for PNGs to be split
across events, we simply refuse to log anything this big.

* Mark RFD 48 implemented

Co-authored-by: Isaiah Becker-Mayer <isaiah@goteleport.com>
Co-authored-by: Edoardo Spadolini <edoardo.spadolini@goteleport.com>
2022-02-11 15:39:14 -07:00
Carson Anderson cc1e13154c Add keepalive heartbeat to kubernetes service (#9584)
This adds an rpc UpsertKubeServiceV2 to replace UpsertKubeService. Currently, kubernetes service does not have a keepalive heartbeat unlike app, db, and windows service. This brings functionality in line with the others. This would allow for future use of the keepalive to track connected agents via prometheus metrics.
2022-02-10 14:54:03 -07:00
Nic Klaassen 37d108ce14 commit forgotten "make grpc" (#10280) 2022-02-10 21:09:40 +00:00
Nic Klaassen bc441ef2cf IAM Join Method (gRPC service) (#10087) 2022-02-10 00:41:34 +00:00
Nic Klaassen e00ff42cb8 IAM Join Method (backend implementation) (#10085) 2022-02-08 18:48:13 +00:00
Edoardo Spadolini 154d6fbf97 Add the cert.create event (#9822)
* Add the `cert.create` event

For now, this is only emitted for user certificate issuance.

* Make `cert_type` a string rather than an enum

* Match field names and json tags in events.Identity

* Change events.Identity.Traits to be a wrappers.LabelValues/wrappers.Traits

* Event code shouldn't be under T10xx anymore
2022-02-08 11:13:35 +00:00
Lisa Kim ab392ef4f6 Add additional filters to ListResources (#10180)
Takes resource parser and match search and 
adds these filters to ListResources.
Allows resource filtering by labels, search keywords, 
or with the predicate language.

Part of RFD 55
2022-02-07 13:12:30 -08:00
Zac BergquistandIsaiah Becker-Mayer 69a96d4b2c Add desktop_clipboard role option (#10165)
* Add desktop_clipboard role option

As described in RFD 49, desktop_clipboard defaults to true.

Since sharing clipboards with a remote machine requires a high level
of trust, the presence of a single role in a role set which disables
the clipboard will result in the feature being disabled.

(This is in contrast to session recording, for example, where all
roles in a set must disable recording to turn it off.)

* completing TestBoolOptions

Co-authored-by: Isaiah Becker-Mayer <isaiah@goteleport.com>
2022-02-07 16:03:43 +00:00
Zac Bergquist 878e71e685 Add role option for record_desktop_session (#9523)
This option defaults to true, as defined in RFD #0033.

The preset editor and audit roles disable desktop session recording,
as they aren't permitted access to desktops. The preset access role
enables desktop session recording. The implicit role applied to all
role sets also disables recording, otherwise it would be impossible
to disable.
2022-02-04 16:06:16 +00:00
Joel 8b7173e803 Use correct unmarshaller for json durations (#10124) 2022-02-03 16:47:51 +00:00
Lisa Kim bbf013ce80 Add MatchSearch to resources for fuzzy search (#9892)
Adds a method to resources MatchSearch, that goes through 
select resource field values, and matches it against a list of 
user provided search values.

Part of RFD 55
2022-01-28 09:18:34 -08:00
Edoardo Spadolini 2598401589 Add access requests to audit events (#9758)
* Refactor most uses of `UserMetadata` into a handful of functions

* Add access requests to `UserMetadata`

* Explanation for the reserved field in SessionStart
2022-01-25 16:56:18 +00:00
Gabriel Corado e426b782a9 feat: add KubeService and Node to ListResources (#9613) 2022-01-25 15:48:13 +00:00
Edoardo Spadolini 95c53ad90e Access request locks (#9478)
* Add access request locks

This only contains the internal part, no user-visible changes

* Add a `tctl lock` flag to specify an access request ID

* Tests for access request locks
2022-01-24 19:40:09 +00:00
Alex McGrath 1ca73cd1e7 Add github teams to available traits 2022-01-24 10:59:59 +00:00
Marek Smoliński 7c8dc2ba05 Fix TLS Router serverName 'kube.' prefix based routing logic (#9777) 2022-01-24 09:53:00 +01:00
Edoardo Spadolini e254076700 Improved Google OIDC connector (#9697)
* go get google.golang.org/api

go get: upgraded cloud.google.com/go v0.60.0 => v0.100.2
go get: upgraded github.com/golang/snappy v0.0.1 => v0.0.3
go get: upgraded github.com/googleapis/gax-go/v2 v2.0.5 => v2.1.1
go get: upgraded go.opencensus.io v0.22.5 => v0.23.0
go get: upgraded golang.org/x/oauth2 v0.0.0-20200107190931-bf48bf16ab8d => v0.0.0-20211104180415-d3ed0bb246c8
go get: upgraded google.golang.org/api v0.29.0 => v0.65.0

* Optionally fetch transitive groups in the Google OIDC connector

* Refactor the google workspace parts of the OIDC code

* Further refactoring

This undoes the user account impersonation changes, and always requires
an admin account again.

* Test coverage

* Address review comments

* Minor refactor and name changes

* Allow domain filtering, tests now bypass addGoogleWorkspaceClaims

* Update `OIDCConnectorV2` to `OIDCConnectorV3`

* Backwards compatibility for OIDCConnector v2

This also removes the extra boolean flag that was added previously.

* Update e-ref

Enterprise builds will break unless gravitational/teleport.e#385
is included.
2022-01-21 18:26:28 +00:00
Tim Buckleyandrosstimothy 6d2ab51d0d Allow impersonation of roles without users (#9561)
* Allow impersonation of roles without users

This adds the ability to impersonate one or more roles without
impersonating a particular user.

In Teleport today, when creating an impersonator role, both users and
roles must be specified as impersonation is fundamentally tied to an
existing Teleport user:
```yaml
allow:
  impersonate:
    users: ['jenkins']
    roles: ['jenkins']
```

This is inconvenient for two reasons:
 1. A user must exist for each set of roles you'd like to
    impersonate, creating a UX burden.
 2. It makes it difficult to use impersonation to reduce one's
    permissions as you always inherit all of the roles granted to the
    target user.

For the [certificate bot][bot] we'd instead like to use impersonation
to generate end-user (impersonated) certificates with a reduced set
of permissions. For example, given the following role:
```yaml
allow:
  impersonate:
    roles: ['jenkins', 'deploy']
```

We can then use `GenerateUserCerts` to issue certifices for a subset
of the allowed roles, e.g. one set of certificates with only the
`jenkins` role attached, and another with only `deploy`.

To that end, this patch:
 1. Removes the requirement that roles define both `users` and
    `roles` in impersonate conditions
 2. Introduces a new `RoleRequests` field in `UserCertsRequest`
 3. Modifies `generateUserCerts` to gather `roles` from
    `RoleRequests` if allowed by an `allow` (with no `users`)

[bot]: https://github.com/gravitational/teleport/pull/7986

* Add `determineDesiredRolesAndTraits`; audit log on role impersonation

This splits initial role and trait determination into a new function,
`determineDesiredRolesAndTraits`, to improve control flow and clarity
given the new branches introduced for role impersonation.

Additionally, this moves the call to `CheckRoleImpersonation` down
to match regular user impersonation's flow, and emits an audit log
event on failure.

* Formatting fix

* Unit testing for role requests

This adds a new set of unit tests for role requests.

Also discovered the `impersonator` field wasn't being set for
role impersonation, so it's now set to the user's own username.
In other words, role impersonation will appear (in the audit log and
elsewhere) as self-impersonation.

* Clean up testing users between runs

* Deny most reimpersonation cases and add tests

This attempts to deny most cases of reimpersonation, where an
impersonated certificate might be used to generate certificates for
other roles the user is allowed to impersonate.

One test case is currently failing pending a solution.

* Add new DisallowReissue certificate extension

This adds a new DisallowReissue certificate extension that, if set,
prevents that identity from interacting with `GenerateUserCerts`.

This flag is always set when RoleRequests are used to prevent
unintended privilege escalation (while avoiding breaking changes to
Teleport's existing certificate generation behavior).

* Fix test lints

* Fix typo

* Fix test doc typo, add testcase for user impersonation misuse

* Apply suggestions from code review

Co-authored-by: rosstimothy <39066650+rosstimothy@users.noreply.github.com>

* Accept context in CreateRole per review feedback

* Fix misleading comment

Co-authored-by: rosstimothy <39066650+rosstimothy@users.noreply.github.com>
2022-01-14 15:15:13 -07:00
Zac Bergquist 20c04df369 Clean up system role parsing (#9756)
* Add tests for ParseTeleportRoles

Updates #9752

* Be more tolerant when parsing system roles.

Our original attempt at canonicalizing roles didn't work for system
roles using camelcase, resulting in an awkward user experience.

Here we maintain a mapping of allowed inputs to their corresponding
system roles, and perform a case-insensitive lookup. This allows us
to support camelcase roles, and has the advantage of permitting
_ word separators as well.

Fixes #9752

* Refactor *SystemRole.Check()

Rather than having to list each role here, we rely on the new
roleMappings set to validate the role.

Additionally, remove the LegacyClusterTokenType role. This change
is guaranteed to be backwards compatible because we check for
RoleTrustedCluster everywhere we were checking for
LegacyClusterTokenType, and our roleMappings will convert the old
string that represented LegacyClusterTokenType to RoleTrustedCluster.
2022-01-14 00:13:59 +00:00
Andrew Burke c0a216ccbe Emit event when connecting to non-Teleport server (#9370)
This change adds a new audit event, `session.connect`, that is emitted when dialing to either an OpenSSH server or a trusted cluster. It also adds `emitConn`, a wrapper for a `net.Conn` that peeks at the first few bytes read and emits session.connect when it detects a non-Teleport connection.
2022-01-13 23:48:13 +00:00
Edoardo SpadoliniandMarek Smoliński c4bb671f2f Add the access_request.delete event (#9552)
* Add the `access_request.delete` event

* fix typo

Co-authored-by: Marek Smoliński <marek@goteleport.com>

* Use a custom RequestID field instead of ResourceMetadata in AccessRequestDelete

This is for consistency with AccessRequestCreate and other FooDelete
events for resources that don't use the Name field in Metadata to
identify the resource.

Co-authored-by: Marek Smoliński <marek@goteleport.com>
2022-01-11 10:56:26 +00:00
Isaiah Becker-Mayer bc11f2dfe6 Adds Desktops to license (#9576)
* Adds Desktops to license

* adds newline
2022-01-06 18:43:47 +00:00
Roman Tkachenko 95be5fda37 Update Postgres audit events (#9435) 2022-01-06 17:44:20 +00:00
Jakub Nyckowski f5d5323f1f Specify level of TLS verification for database connections (#9197)
Now 'verify-full', 'verify-ca' and 'insecure' modes can be used when connecting to a database. 'verify-full` is the default on and it's the most strict. 'verify-ca' skips the server-name check. 'insecure' accepts any certificate provided by a database.
2022-01-05 16:41:49 +00:00
Edoardo Spadolini 3a50ffab26 Add access requests to TLS certificates (#9501)
* Add access requests to tlsca.Identity, and store them in TLS certs

This mirrors what we already do for SSH certs.

* Keep track of access requests in web sessions

* Keep track of access requests in app sessions

* Include the current access requests when issuing new user certs

This is necessary because we extend the list of current roles
instead of starting from the statically assigned ones, so we should
also keep track of all the potential ways that those roles were
granted to the user.

* fix: pass access requests through PreAuthenticatedSignIn

* Tests for access requests in TLS certs
2022-01-03 14:22:16 +00:00