Commit Graph
625 Commits
Author SHA1 Message Date
Andrew Burke 4543bfd98d Respect HTTP_PROXY/HTTPS_PROXY (#10209)
This change allows tsh to use HTTP proxies when HTTP_PROXY/HTTPS_PROXY is set in the environment.
2022-03-23 19:58:19 +00:00
Alan Parra b2c5c8ecb0 Add FIDO2 passwordless login and registration to tsh (#11321)
Passwordless login is enabled by the global `--pwdless` flag. Registration gets
a new prompt and an `--allow-passwordless` flag.

UX messages were tweaked to follow the descriptions on RFD 53: Passwordless
FIDO2[1].

Passwordless login requires two touches for all devices (both PIN and biometric).
I'd like to get it down to a single touch, at least for the most common
situations, but that'll be a follow up to this work.

Passwordless support requires `tsh` to be compiled with the `libfido2` tag, try
`go build -tags=libfido2 ./tool/tsh`.

#9160

[1] https://github.com/gravitational/teleport/blob/master/rfd/0053-passwordless-fido2.md#ux

* Allow reuse of devices for passwordless
* Implement passwordless registration in tsh
* Add better tracing to FIDO2 filters
* Implement passwordless logins in tsh
* Make --pwdless a global flag
* Fix lint errors
* Fix U2F tests
* Use initClient's URL as origin
* Distinguish whether --allow-passwordless is set or unset
2022-03-23 18:38:10 +00:00
Zac Bergquist 8521b388f2 Remove legacy JSON API for host certs (#11330)
This is a follow up to e256170d60.
Now that Teleport 9 is out, we can remove the last traces of
this API for Teleport 10.
2022-03-23 17:57:22 +01:00
Alex McGrath 3d35263a6c Add a .tsh/config file and add support for configuring custom http headers 2022-03-23 14:19:07 +00:00
Zac Bergquist 55cbd0ac97 Remove use of deprecated ioutil package (#11296)
* Remove use of deprecated ioutil package
* Add lint rule to check for ioutil imports
2022-03-21 18:00:34 +00:00
Alan Parra 023f533be2 Wire FIDO2 into tsh login and registration (#11241)
Seamlessly change the public API of lib/auth/webauthncli to use the
libfido2-backed implementation, as long as the binary was compiled with the
libfido2 build tag.

A few adjustments are necessary to "wancli" methods to allow users to provide
prompt callbacks and to return the credential user (not applicable here, but
will be in following PRs).

Additional changes are made to tsh mfa add in order to avoid stdin hijacking by
ContextReader, since we now may require PIN reads for authenticators.

#9160

* Move U2F logic to u2f_* files
* Split U2F API from general l/a/webauthncli API
* Move FIDO2 public API to fido2_common.go, introduce IsFIDO2Available
* Introduce prompt.SyncReader

Sync reads allow prompt calls to be mixed with term.ReadPassword calls.

* Wire FIDO2 into MFA login
* Wire FIDO2 into MFA registration
2022-03-21 14:35:08 +00:00
Alex McGrath 39977efc00 Add tests for motd fixes
Part of this includes renaming export_test.go to export.go so I could
test the MOTD outside of lib/client/export.go
2022-03-15 12:18:39 +00:00
Alex McGrath de9bdf086d Fix MOTD not showing up on tsh login with certain arguments
- changes to configuration.go: fixes tsh login in first test case
  `tsh login --insecure --proxy=127.0.0.1:3080 --user=test`
- changes to apiserver.go fixes `--auth` not showing motd
2022-03-15 12:18:39 +00:00
Joel 92543d9b3e Moderated Sessions improvements (#10991) 2022-03-10 23:04:12 +00:00
rosstimothy 550d23d15d Fix goroutine and memory leak in watchCertAuthorities (#10871)
* Fix goroutine and memory leak in watchCertAuthorities

The CA Watcher was blocking both on writing to a channel when the watcher
was closed and on HTTP calls that had no request timeout or context passed
to cause cancellation.

All resourceWatcher implementations that had a bug which may cause them to block
on writing to a channel forever were fixed by selecting on the write and ctx.Done.

Adding context.Context to all Get/Put/Post/Delete methods on the auth HTTPClient to
force callers to propagate context. Prior all calls used context.TODO which
prevents requests from being properly cancelled.

Add context propagation to RotateCertAuthority, RotateExternalCertAuthority,
GetCertAuthority, GetCertAuthorities. This is needed to get the correct ctx
from the CertAtuhorityWatcher all the way down to the HTTPClient that makes
the call.

Closes #10648
2022-03-10 11:05:39 -05:00
Lisa Kim 350ea5bb95 Updates tsh ls for node/app/db/kube to accept new filter flags (#10980)
* Also adds a search keyword parser that takes in different
  delimiters (comma is used for tsh, space is used for web UI)

part of RFD 55
2022-03-09 23:56:55 +00:00
Przemko Robakowski 18e8e985ad Disable OTP code echoing in terminal (#10953)
This hides OTP input in CLI the same way we do for passwords
2022-03-09 19:54:22 +00:00
Brian Joerger 600022b290 Change NewRole to use V5 by default, old consumers now user NewRoleV3. (#10884) 2022-03-08 21:11:53 +00:00
Alan Parra 5023235909 Add passwordless login/registration to auth and web (#10632)
Wire passwordless registration and authorization into Auth and Proxy APIs, thus
making passwordless logins possible.

API changes are described by RFD 52: Passwordless [1].

#9160

[1] https://github.com/gravitational/teleport/blob/master/rfd/0052-passwordless.md#authentication-api-changes

* Add passwordless settings to Auth protos
* Update generated protos
* Register: Apply DeviceUsage in lib/auth
* Register: Apply DeviceUsage in lib/web
* Login: Generate passwordless challenge
* Login: Allow passwordless authentication
* Wire passwordless in lib/web endpoints
* Make mocku2f passwordless setup a bit nicer
2022-03-04 18:41:35 +00:00
Takao Shibata 299941358e prompt to stderr instead of stdout when login
`tsh kube credentials` command is executed as kubernetes client-go
credential plugins.
https://kubernetes.io/docs/reference/access-authn-authz/authentication/#client-go-credential-plugins

client-go captures all stdout of plugin and treats it as
`ExecCredential` object.

When session is timeout, `tsh` prompt to relogin.
To avoid client-go's capturing prompt text, prompt to stderr instead of
stdout when login.
2022-03-02 18:41:50 -08:00
Lisa Kim e7eb6c4af8 Return filtered total count with ListResources (#10573)
* The web UI needed to show the total count of resources available after filter
* ListResources response returns as a struct to make adding extra fields easier
2022-02-28 21:51:19 +00:00
Alan Parra bac0ccdc99 Remove U2F support (#10476)
Follows up on #10466 by removing remaining U2F references, including proto/gRPC
surface and the lib/auth/u2f package itself.

#10375

* Remove U2F from lib/auth/ (1)
* Remove U2F from lib/auth/ (2)
* Remove U2F from lib/auth/ (3)
* Remove U2F from lib/services/
* Remove U2F from tsh mfa add suggestions
* Remove U2F protos
* Update generated protos
* Cleanup a few stragglers
* Remove lib/auth/u2f package
* Fix references to auth.MFAAuthenticateChallenge
* Revert needless lib/auth/password.go change
* Update e/ to ad8fd4a (U2F cleanup)
* Fix stragglers from latest master rebase
* Fix lint and compile failures
2022-02-24 19:54:28 +00:00
Alan Parra f8b7b330ad Alias "u2f" to "webauthn" and partially cleanup (#10466)
Alias the "u2f" second factor mode to "webauthn", effectively sunsetting U2F in
favor of WebAuthn.

The change effectively disables "U2F mode" server-side, making Teleport use
WebAuthn instead. This is in line with our compatibility promise, as Teleport
8.x clients are already WebAuthn-capable (and thus have no problems talking to
the cluster).

I have cleaned up a good chunk of U2F references in lib/web and lib/client, plus
a few other places. Changes on lib/auth are just the necessary to get the tests
back to good standing. There is more work to be done, but this seems enough for
a single PR.

#10375

* Remove "Disabled" field from types.Webauthn
* Update generated protos
* Treat second_factor "u2f" as "webauthn"
* Remove references to Webauthn.Disabled
* Remove U2F from lib/web/
* Remove U2F from lib/client/
* Remove U2F from lib/auth/ (partially)
* Fix issues after rebase on master
* Fix typo
2022-02-23 14:10:13 +00:00
Marek Smoliński 28907e17a0 Add MFA for Windows Desktop web access (#10271) 2022-02-18 22:01:46 +00:00
Andrew Burke 4e3bd6c647 Clear terminal when auth server is in FIPS mode (#10095)
This change clears the terminal at the end of a session when the auth server is in FIPS mode, even if tsh isn't.
2022-02-17 10:16:36 -08:00
Jakub Nyckowski 530ff4c402 Add Redis integration (#10053)
Add support for Database Access for Redis for standalone and cluster self-hosted instances. Teleport requires mTLS in order to connect to Redis instance which is only supported in Redis 6.0+. RESP2 is currently the only supported protocol.
2022-02-16 13:32:32 -05:00
Zac Bergquist e256170d60 Remove the legacy JSON API for requesting host certs
In Teleport 8 we migrated all uses of this API to GRPC, but left
the JSON API in place so that Teleport 7 nodes could still join
the cluster.

In Teleport 9, the oldest nodes we support are v8, which use the
GRPC API, so we can safely remove the old API.
2022-02-15 18:40:48 -07:00
Joel ea810d30d9 Implement Moderated Sessions (#8563)
* Implement Moderated Sessions
2022-02-15 17:02:10 +01:00
c84b7f8142 Desktop session recording/playback (#9583)
* Record desktop sessions

Here we introduce a new protobuf type (DesktopRecording) that contains
an encoded TDP message, and update AuditWriter to treat these similarly
to SessionPrint events (which are used for SSH session recordings).

We also add desktop session playback endpoint, temporarily located at
/webapi/sites/:site/desktopplaybacktest/:session
which streams TDP messages from a recorded session over
a websocket interface.

* update session end (#9795)

* Updates SessionEnd event with fields needed for frontend

* removes the clock which didn't need to be passed

* Add `Recorded` field to `WindowsDesktopSessionEnd` (#9839)

* Adds the SessionRecording field to WindowsDesktopSessionEnd event to mimic SessionEnd events (useful for easy integration with frontend).

* 14 should have been 12

* removing test logic

* switches SessionRecording to simple boolean Recorded

* session recording websocket (#9908)

* Adds the SessionRecording field to WindowsDesktopSessionEnd event to mimic SessionEnd events (useful for easy integration with frontend).

* 14 should have been 12

* removing test logic

* switches SessionRecording to simple boolean Recorded

* Updates the websocket address

* updates desktopPlaybackHandle to restart playback once it reaches the end

* adds playback state and synchronization logic for ensuring that goroutines aren't leaked

* adds toggle functionality for play/pause

* fix for the fact that urls are case insensitive

* moves desktop_playback to its own file, fixes mistaken comment about how websocket.JSON.Receive works, fixes error messaging, wraps playbackState.Close in a sync.Once

* Adds a cond variable for the two goroutines, but doesn't solve the spinning loop problem for the hanging logic

* Adds a cancel-able context which is cancelled in ps.Close() in order to avoid a spinning loop in the websocket.Handler

* Moves the majority of playback logic into the playbackState, which is now renamed to the more accurate playbackPlayer.

* changes pp.hangWhilePaused to pp.waitWhilePaused

* Moves the context out of NewPlaybackPlayer and the playbackPlayer
struct, wraps playback goroutines in playbackPlayer.Play(ctx) in
order to comply with context semantics.

* removing unnecessary warnings

* touchups

* record screen size (#9992)

* Adds the SessionRecording field to WindowsDesktopSessionEnd event to mimic SessionEnd events (useful for easy integration with frontend).

* 14 should have been 12

* removing test logic

* switches SessionRecording to simple boolean Recorded

* Updates the websocket address

* updates desktopPlaybackHandle to restart playback once it reaches the end

* adds playback state and synchronization logic for ensuring that goroutines aren't leaked

* adds toggle functionality for play/pause

* fix for the fact that urls are case insensitive

* moves desktop_playback to its own file, fixes mistaken comment about how websocket.JSON.Receive works, fixes error messaging, wraps playbackState.Close in a sync.Once

* Adds a cond variable for the two goroutines, but doesn't solve the spinning loop problem for the hanging logic

* Adds a cancel-able context which is cancelled in ps.Close() in order to avoid a spinning loop in the websocket.Handler

* Moves the majority of playback logic into the playbackState, which is now renamed to the more accurate playbackPlayer.

* changes pp.hangWhilePaused to pp.waitWhilePaused

* Moves the context out of NewPlaybackPlayer and the playbackPlayer
struct, wraps playback goroutines in playbackPlayer.Play(ctx) in
order to comply with context semantics.

* removing unnecessary warnings

* Adds an OnRecv that's similar to OnSend, for emitting audit events for particular incoming tdp messages

* Send full `DesktopRecording` event as json over playback websocket. (#10052)

* playback websocket now sends a json representation of the DesktopRecording event rather than just the raw tdp message, in order for us to have timing data on the frontend

* updating json.Marshal to utils.FastMarshal

* Removing unnecessary comment

* playback end event (#10088)

* Adds an end event so that the playback player knows to set the progress bar to its end state

* making the end message a json

* if the marshal fails we don't want to send a message over websocket

* Use a static string

Co-authored-by: Edoardo Spadolini <edoardo.spadolini@goteleport.com>

Co-authored-by: Edoardo Spadolini <edoardo.spadolini@goteleport.com>

* Add participants to session end event

Desktop sessions are not joinable, so the participants list always
has a single member - the user who started the session.

This will ensure that our example role for RBAC for sessions
(which depends on the participants field) will work for desktop
sessions.

* Minor cleanup

* Only record sessions when enabled

In order for desktop sessions to be recorded, session recording
must be enabled in the cluster's session recording config and
at least one of the user's roles must enable it.

* Cleanup

* Start to address review comments

* Move TDP event handlers out of connectRDP

* Address more review comments and add some tests

* Add playback streaming test

* Consistent comments

* Fix tests

* Don't log PNG frames that exceed the size of a protobuf

Since the PNG frame message in our desktop protocol is unbounded,
it is theoretically possible for a message to exceed the size limit
of a single protobuf.

In practice, this is unlikely to occur with any legitimate RDP traffic,
as the bitmaps are at most 64x64 pixels and compressed in PNG form.
Rather than complicating the protocol to allow for PNGs to be split
across events, we simply refuse to log anything this big.

* Mark RFD 48 implemented

Co-authored-by: Isaiah Becker-Mayer <isaiah@goteleport.com>
Co-authored-by: Edoardo Spadolini <edoardo.spadolini@goteleport.com>
2022-02-11 15:39:14 -07:00
Brian Joerger d33f51d17f x11 forwarding (#9897) 2022-02-04 23:47:03 +00:00
Marek Smoliński fbd5a2aafd Fix tsh tctl do not load all CAS (#9357) 2022-01-31 13:35:15 +01:00
Gabriel Corado e426b782a9 feat: add KubeService and Node to ListResources (#9613) 2022-01-25 15:48:13 +00:00
JoelandZac Bergquist 62173e096b use google/uuid instead of pborman/uuid (#9793)
* replace imports

* use google/uuid

* fix test

* reverse changelog changes

* update gomod

* zac steps

* tidy

Co-authored-by: Zac Bergquist <zac.bergquist@goteleport.com>
2022-01-19 23:44:48 +00:00
Jakub Nyckowski a2e83ab36f Retry with re-login ignores TELEPORT_HOME. (#9436)
Set correct home directory after `tsh` re-logins the user.
2022-01-19 19:04:22 +00:00
Jakub Nyckowski bae67b3c95 Add support for MariaDB (#9409)
Add support for MariaDB client and update documentation.
2022-01-10 20:12:31 -05:00
Alex McGrath d89dfe967e tool/tsh: support ID for tsh play -f json 2021-12-16 13:09:51 +00:00
Gabriel Corado 5f403562ab feat: ListResources gRPC rpc (#9096) 2021-12-15 18:09:21 +00:00
Marek Smoliński f906831e58 Add ability to run Mongo proxy on separate listener (#9194) 2021-12-14 14:26:14 +01:00
Marek Smoliński d24ae5b1ce Add ability to run Postgres proxy on separate listener (#8323) 2021-12-10 11:05:19 +01:00
STeve Huang 4e3f795e8f Add --cluster flag to all tsh db subcommands, Add "--diag_addr" flag to teleport db/app start (#9220)
* add diag to teleport db/app start

* db --cluster flag supports

* add some ut and fix issue ~/.tsh get removed during test

* working mongodb

* fix logout

* fix ut

* code review comment

* fix mysql
2021-12-09 11:24:39 -05:00
699f588072 Clear web terminal when session ends (#8850)
This change clears the screen when an ssh session ends (only in FIPS mode). Note: This doesn't currently do anything in `tsh` on Windows since BoringCrypto isn't supported, but once it is supported, the behavior will match Unix and web.

Co-authored-by: Grzegorz <grzegorz.zdunek@goteleport.com>
Co-authored-by: Russell Jones <russjones@users.noreply.github.com>
2021-12-02 12:48:27 -08:00
Alan Parra 8b0976539a Do not prompt for hardware MFA using tsh on Windows (#9081)
`tsh` doesn't support MFA logins on Windows; we make that explicit by warning
users when necessary, instead of directing them to a hopeless workflow.

Example attempt:

```shell
$ tsh login
> Enter password for Teleport user codingllama: <password>
> ERROR: hardware device MFA not supported by your platform, please register an OTP device
>
> exit status 1
```
2021-12-02 11:34:49 -08:00
Zac Bergquist 53562aadb0 Use t.Setenv in tests (#9154)
This new feature in Go 1.17 automatically restores the environment
variable to its previous value when a test ends, making it simpler
to set up the environment for tests and less likely that we accidentally
leave behind global state.

Also convert some of the remaining uses of check to standard Go tests.
2021-12-01 10:43:12 -07:00
Marek Smoliński 71396872f1 Fix KUBECONFIG server name (#8940) 2021-11-12 22:32:42 +01:00
Marek Smoliński c335534e02 Fix tsh ssh proxy (#8826) 2021-11-05 13:30:10 +01:00
rosstimothy 5cd7c3c294 Split auth.AccessPoint into variant specific interfaces (#8471) 2021-11-04 09:42:14 -04:00
Roman Tkachenko d87ee8f640 Fix mongo access with mfa and add tests (#8799) 2021-11-02 12:06:58 -07:00
Roman Tkachenko 9bf88bef01 URL-encode Postgres username in connection string (#8771) 2021-11-01 08:40:06 -07:00
Nic Klaassen f884cdd7e3 Make RegisterUsingTokenRequest a Protobuf type (#8690) 2021-10-27 10:59:44 -07:00
Forrest Marshall 19c5768873 server-side filtering 2021-10-22 16:42:33 -07:00
Marek Smoliński 17a5cadabb Add Proxy listener mode and proxy v2 configuration (#8511) 2021-10-21 14:45:47 +02:00
Marek Smoliński 7606d330e9 AWS CLI access (#8151) 2021-10-19 10:43:53 +02:00
Lisa Kim 4ce2771a4c Consistent webauthn JSON field naming for web (#8559)
* removes underscores
* created a new handler to replace a deprecated handler:
   webapi/u2f/password/changerequest
2021-10-13 11:11:39 -07:00
Roman Tkachenko 36998cf566 Add CockroachDB support (#8505) 2021-10-12 14:30:59 -07:00
Marek Smoliński 700f9f71e5 Add support for MFA for DB access (#8270) 2021-10-06 13:59:35 -07:00