Commit Graph
3310 Commits
Author SHA1 Message Date
Zac Bergquist 82943f38dd AuditLog: Remove unused EventsC
This was used to test legacy audit log behavior, which has since
been removed.
2022-03-25 15:21:22 -06:00
Zac Bergquist 4e2e834b68 Remove unused DiskSessionLogger 2022-03-25 15:21:22 -06:00
Zac Bergquist bd7e7a84f0 Remove events.Forwarder and RecordSessions config param
The Forwarder type has been replaced with the new GRPC/streaming based
session recording and was only used in tests.

The RecordSessions param is never consulted, as it was replaced with
AuditWriter's RecordOutput param a couple of years ago.
2022-03-25 15:21:22 -06:00
Zac Bergquist 58b2aac411 Remove unused GRPC service 2022-03-25 15:21:22 -06:00
Zac Bergquist 3dc33ccc32 lib/events: remove more old code
This removes support for the pre-5.1.0 streaming directory, and
removes the unused Recorder type.
2022-03-25 15:21:22 -06:00
Zac Bergquist 62f687bef7 lib/events: remove legacy event types
These events are remnants of the old system before our events
were strongly-typed protos, and were unused in the code
(save for a few tests, which were updated)
2022-03-25 15:21:22 -06:00
Gabriel Corado 58ca1bdbb0 fix(db): send initial heartbeat when there is no static dbs (#11160) 2022-03-25 20:17:54 +00:00
STeve (Xin) Huang fd12e934ee RDS & Redshfit support for AWS China regions (part 1?) (#10560) 2022-03-25 17:40:51 +00:00
Alan Parra 5a11006f81 Add ReadPassword functionality to ContextReader (#11436)
This changes prompt.ContextReader in the following ways:

Reads only happen as a response to Read methods being called. This allows
ContextReader to coexist with other readers as long as no reads are abandoned.
ReadPassword is now available, the underlying implementation being
term.ReadPassword. An abandoned password read may be turned into a clean read.
This gives us some UX flexibility when callers abandon password reads (looking
at you, PromptMFAChallenge). Turning clean reads into password reads is not
supported. It's tricky and I have a few ideas, but it's not paramount at this
moment.

This solves the woes caused by abandoned OTP reads followed by PIN reads in
different packages, such as client.PromptMFAChallenge followed by tsh mfa add's
implementation.

#9160

* Move ContextReader to its own file
* Refactor ContextReader and implement ReadPassword
* Test ReadPassword
* Fix typos
* Remove prompt.StdinSync()

prompt.Stdin() has the same behavior for non-abandoned reads.

* Group /x/term methods under a type
2022-03-25 17:17:20 +00:00
Marek Smoliński 335adf1f4e Don't respect HTTP_PROXY env in k8 forwarder (#11257) 2022-03-25 13:49:59 +01:00
Edoardo Spadolini 4384c354ff Reexec with /proc/self/exe on Linux (#11283)
* Reexec with `/proc/self/exe` on Linux

* Add a check for qemu-user

* Add comment
2022-03-25 10:16:43 +00:00
Joel 90a0ff54b9 Limit stdout/stderr buffering in paused sessions (#11347) 2022-03-24 21:19:56 +00:00
Carson AndersonandPaul Gottschling 4054c79c7e Add metric to track number ssh connect attempts (#11240)
* add ssh connect attempts metric

* fix help message wording

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
2022-03-24 20:34:00 +00:00
Forrest Marshall 50d767d304 improve cache test perf 2022-03-24 12:52:20 -07:00
Jeff Pihach 4c0df63633 Move the install.sh script into the oss version and import it on build instead of requiring a copy/paste to update. (#11352) 2022-03-24 19:22:48 +00:00
Joel 30647c455b Set podname before message uses it (#11286) 2022-03-24 14:42:00 +00:00
Joel 0bd0b234e3 Update cargo deps (#11400) 2022-03-24 12:15:13 +00:00
Forrest 5bd9434ab1 improve ca cmp (#10351) 2022-03-23 23:08:38 +00:00
James PerryandZac Bergquist 536671b541 set err to scanner.Err (#11100)
Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>
2022-03-23 22:31:38 +00:00
rosstimothy 487ba57a3c Fix panic in getWebConfig (#11389)
Refactored the usage of the types.AuthPreference returned from
GetAuthPreference so that it is only accessed if there were no
errors.
2022-03-23 17:54:25 -04:00
Andrew Burke 4543bfd98d Respect HTTP_PROXY/HTTPS_PROXY (#10209)
This change allows tsh to use HTTP proxies when HTTP_PROXY/HTTPS_PROXY is set in the environment.
2022-03-23 19:58:19 +00:00
Zac Bergquist 6277ef8620 Remove LDAP password_file from configuration (#11331)
When we deprecated the password_file option for Teleport 9, we left
the configuration property in the config so that we could give v8
users who had recently upgraded a nice error message letting them
know that we deprecated this field.

For Teleport 10, everyone coming from v9 will have already removed
this property, so the deprecation warning is no longer necessary.
2022-03-23 19:34:30 +00:00
STeve (Xin) Huang 3d7de736e3 Improve cli usage when command name is long (#10981) 2022-03-23 19:08:42 +00:00
Alan Parra b2c5c8ecb0 Add FIDO2 passwordless login and registration to tsh (#11321)
Passwordless login is enabled by the global `--pwdless` flag. Registration gets
a new prompt and an `--allow-passwordless` flag.

UX messages were tweaked to follow the descriptions on RFD 53: Passwordless
FIDO2[1].

Passwordless login requires two touches for all devices (both PIN and biometric).
I'd like to get it down to a single touch, at least for the most common
situations, but that'll be a follow up to this work.

Passwordless support requires `tsh` to be compiled with the `libfido2` tag, try
`go build -tags=libfido2 ./tool/tsh`.

#9160

[1] https://github.com/gravitational/teleport/blob/master/rfd/0053-passwordless-fido2.md#ux

* Allow reuse of devices for passwordless
* Implement passwordless registration in tsh
* Add better tracing to FIDO2 filters
* Implement passwordless logins in tsh
* Make --pwdless a global flag
* Fix lint errors
* Fix U2F tests
* Use initClient's URL as origin
* Distinguish whether --allow-passwordless is set or unset
2022-03-23 18:38:10 +00:00
Zac Bergquist 8521b388f2 Remove legacy JSON API for host certs (#11330)
This is a follow up to e256170d60.
Now that Teleport 9 is out, we can remove the last traces of
this API for Teleport 10.
2022-03-23 17:57:22 +01:00
Alex McGrath 3d35263a6c Add a .tsh/config file and add support for configuring custom http headers 2022-03-23 14:19:07 +00:00
Zac Bergquist 55cbd0ac97 Remove use of deprecated ioutil package (#11296)
* Remove use of deprecated ioutil package
* Add lint rule to check for ioutil imports
2022-03-21 18:00:34 +00:00
Alan Parra 023f533be2 Wire FIDO2 into tsh login and registration (#11241)
Seamlessly change the public API of lib/auth/webauthncli to use the
libfido2-backed implementation, as long as the binary was compiled with the
libfido2 build tag.

A few adjustments are necessary to "wancli" methods to allow users to provide
prompt callbacks and to return the credential user (not applicable here, but
will be in following PRs).

Additional changes are made to tsh mfa add in order to avoid stdin hijacking by
ContextReader, since we now may require PIN reads for authenticators.

#9160

* Move U2F logic to u2f_* files
* Split U2F API from general l/a/webauthncli API
* Move FIDO2 public API to fido2_common.go, introduce IsFIDO2Available
* Introduce prompt.SyncReader

Sync reads allow prompt calls to be mixed with term.ReadPassword calls.

* Wire FIDO2 into MFA login
* Wire FIDO2 into MFA registration
2022-03-21 14:35:08 +00:00
Przemko Robakowski 35a9bbc887 Use first available auth server (#11229)
Currently we use random auth server from the list but if it's unavailable (for example it was restarted but there's still entry in cache, dynamodb backend etc) we return error.
This change tries all servers (in random order) and uses first that is available.

Closes #10019
2022-03-18 22:15:54 +00:00
Alan Parra 84127a557d Implement FIDO2 login and registration (#11166)
Implements CLI login and registration using go-libfido2. Covers both MFA and
passwordless use cases.

The FIDO2 implementation is akin to the existing U2F Login / Registration logic,
including a similar "device detection" loop. A few notable differences are:

A filtered "device search" step that ends as soon a suitable device is found A
more explicit "device selection" step, which makes it easier to implement PIN
flows The MFA UX for end-users should remain mostly unaltered.

There are no separate methods for MFA and passwordless, as much of the logic
would be the same. Instead, the methods react to the assertion/credential
parameters accordingly.

At this moment this code is isolated from other callers, as well as from our
build processes via the libfido2 tag. This is to avoid impact to other
developers, as go-libfido2 has a few requirements before it can be downloaded or
executed.

#9160

* Import github.com/keys-pub/go-libfido2
* Implement FIDO2 login
* Add login tests
* Implement FIDO2 registration
* Add registration tests
2022-03-18 15:14:24 +00:00
Zac Bergquist c239344649 Remove legacy session backend key (#11123)
Noticed this old code while working on a separate change.
2022-03-18 14:37:12 +00:00
NajiObeid 16bf416556 fix loggers not respecting json config (#10808) 2022-03-18 04:36:06 +00:00
Zac BergquistandPaul Gottschling 072956e4a0 docs: clarify /healthz and /readyz (#11085)
- Rename the page, since it's about diagnostics rather than metrics
  alone
- Change major section headings to H2s so they apper in the table of
  contents
- Move information about heartbeats and recovery to an H3 so it's
  more visible

Updates #10799

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
2022-03-17 16:46:12 +00:00
Edoardo Spadolini 257d005ca3 Revert "Only allow access request deletion through static roles' permissions (#9540)" (#11220)
This reverts commit 8db6aa5883.
2022-03-17 16:18:16 +00:00
Edoardo Spadolini 160df0086a Support role bootstrapping in OSS (#11175)
* Add role bootstrapping

* Test coverage

* Better variable names

* Remove spurious log, add better error messages
2022-03-17 10:12:18 +00:00
Zac Bergquist 3f507dfd06 Remove uses of deprecated ioutil package 2022-03-16 15:05:42 -06:00
Zac Bergquist 77fbed70ce Clean up cgroups.go
Prefer package filepath over package path when working with the
filesystem.

Stop using the deprecated ioutil package.
2022-03-16 15:05:42 -06:00
Edoardo Spadolini 4d99f1c9cf Keep multiple per-node remoteConns in localSite (#11074) 2022-03-16 12:17:49 +00:00
Edoardo Spadolini d83886e9c3 Address problems in concurrent sqlite access (#10706)
* Use BEGIN IMMEDIATE to start transactions

This makes it so all transactions grab a write lock
rather than a read lock that can be upgraded in case of
a write; in case of multiple writers (which, in our
case, can only happen during a restart as the new
process reopens the same sqlite database) this will
prevent two transactions from attempting to upgrade
their lock, which would cause a SQLITE_BUSY error in
one of them. In regular operation this shouldn't cause
a performance hit, as we're using a single connection
to the sqlite database (guarded by locks in the go side)
anyway.

* Escape path in sqlite connection URL

This makes it so that the sqlite backend supports paths with ? in them.

* Close process storage on TeleportProcess shutdown

This aligns the behavior of Shutdown with that of Close.

* Allow specifying the journal mode in sqlite

This will let sqlite backend users specify WAL mode in their config
file, and will allow us to specify alternate journal modes for our
on-disk caches in the future.

This also removes sqlite memory mode, as it's not used anywhere because
of its poor query performance compared to our in-memory backend, and
cleans up a bit of old cruft, and runs process storage in FULL sync
mode - it's very seldom written to and holds important data.
2022-03-15 16:54:48 +00:00
STeve (Xin) Huang 0d12750b78 Common database connect errors (#11111) 2022-03-15 16:28:23 +00:00
STeve (Xin) Huang c167bb46db fix panic child.Close() called without logger initialized (#11117) 2022-03-15 14:57:34 +00:00
Alex McGrath 26f7f179cb Fix certificate extension not being included in tctl auth sign 2022-03-15 14:10:29 +00:00
Alex McGrath 40200e8536 Reslove comments, move all occurences of teleport.dev to use a constant 2022-03-15 13:22:45 +00:00
Alex McGrath b6df9a742a Add verbosity to tctl * ls commands and resource get. 2022-03-15 13:22:45 +00:00
Alex McGrath ad41b3c154 Move 'MakeTableWithTruncatedColumn' to asciitable and truncate labels 2022-03-15 13:22:45 +00:00
Alex McGrath cdae4e3ee2 ls consistency: add support for tctl desktop ls
```
Host Public Address       AD Domain   Labels               Version
---- -------------------- ----------- -------------------- ---------
corn 192.168.122.144:3389 example.com teleport..3 (9       9.0.0-dev
corn 192.168.122.51:3389  example.com teleport.rd Evle.com 9.0.0-dev
```

```yaml
kind: windows_desktop
metadata:
  expires: "2022-02-18T16:12:52.422659238Z"
  id: 1645200172423989197
  labels:
    teleport.dev/computer_name: WIN-LA2V0OD7SK0
    teleport.dev/dns_host_name: WIN-LA2V0OD7SK0.example.com
    teleport.dev/is_domain_controller: "true"
    teleport.dev/origin: dynamic
    teleport.dev/os: Windows Server 2012 R2 Standard Evaluation
    teleport.dev/os_version: 6.3 (9600)
    teleport.dev/windows_domain: example.com
  name: WIN-LA2V0OD7SK0-example-com
spec:
  addr: 192.168.122.51:3389
  domain: example.com
  host_id: 2c807641-92ae-4c70-88fe-b93e7b0aa179
version: v3
```
2022-03-15 13:22:45 +00:00
Joel 35942e92ce Fix quit on ctrlc, race panic, atomic load align in session IO (#11112) 2022-03-15 12:57:46 +00:00
Alex McGrath 39977efc00 Add tests for motd fixes
Part of this includes renaming export_test.go to export.go so I could
test the MOTD outside of lib/client/export.go
2022-03-15 12:18:39 +00:00
Alex McGrath de9bdf086d Fix MOTD not showing up on tsh login with certain arguments
- changes to configuration.go: fixes tsh login in first test case
  `tsh login --insecure --proxy=127.0.0.1:3080 --user=test`
- changes to apiserver.go fixes `--auth` not showing motd
2022-03-15 12:18:39 +00:00
Krzysztof Skrzętnicki 3bbd3fc68c Automatically calculate public_addr field for dynamic apps (#10941). (#10943)
* Autodiscover public_addr for dynamic apps.
2022-03-15 12:51:11 +01:00