Commit Graph
185 Commits
Author SHA1 Message Date
Zac Bergquist 55cbd0ac97 Remove use of deprecated ioutil package (#11296)
* Remove use of deprecated ioutil package
* Add lint rule to check for ioutil imports
2022-03-21 18:00:34 +00:00
Brian Joerger 1b08e7d0db Handle case where display is itself a unix socket #10719 2022-03-08 23:51:59 +00:00
Brian Joerger a03d867771 Fix x11 server config issues (#10471) 2022-02-25 19:30:48 +00:00
Brian Joerger 172d7ed4c0 Update x11 sshserver test to test concurrent sessions and requests. (#10470) 2022-02-18 22:23:02 +00:00
Brian Joerger 8a4acb9ffe Replace /tmp with os.TempDir(). (#10322) 2022-02-14 18:39:22 +00:00
Brian Joerger d33f51d17f x11 forwarding (#9897) 2022-02-04 23:47:03 +00:00
Marek Smoliński fbd5a2aafd Fix tsh tctl do not load all CAS (#9357) 2022-01-31 13:35:15 +01:00
Alan Parra 85a6a0ca46 Improve SSH agent forwarding error message in proxy mode (#8829)
Proxy mode requires SSH agent forwarding permissions to work properly.
This tweaks the error message to mention that in a more direct manner.

Previous message:

$ tsh ssh mynode
> ERROR: failed connecting to node mynode. agent forwarding not requested or not authorized

New message:

$ tsh ssh mynode
> ERROR: failed connecting to node mynode. agent forwarding required in proxy recording mode
2021-11-10 13:33:28 -08:00
Forrest Marshall cf7d221b64 improve graceful restart behavior 2021-09-21 11:56:39 -07:00
Roman Tkachenko e1c3f80aa0 Fixes for cert checker and Postgres config builder (#8251) 2021-09-17 13:28:40 -07:00
Alan Parra dba49bfad6 Lint and fix missing license headers (#8075)
Introduce new make targets to check and add license headers to files
("make lint-license" and "make fix-license"). License checking is now a part of
"make lint" as well.

Initial attempts used goheader, but it caused "make lint-go" to become about 9x
slower (if not more), plus it only targets go files. Google's addlicense is fast
enough and targets however many file types we want.

Existing files that were missing licenses got the header added, using the
current year as the license date.

* Introduce lint-license and fix-license make targets
* Ignore generated files
* Add license to go files
* Replace irregular licenses with standard copyright/license
* Add license to proto files
* Install addlicense in build.assets Dockerfile
2021-08-30 09:44:09 -07:00
Nic Klaassen a8db09fe1e Use KeyStore instead of raw keys with CAs (#7615) 2021-08-03 10:13:08 -07:00
Brian Joerger 9b8b9d6d0c rollback - Upgrade api version. (#7751) 2021-07-30 15:34:19 -07:00
Brian Joerger c040aca4c1 Upgrade api version. (#7609) 2021-07-28 13:51:21 -07:00
Andrew Lytvynov d4247cb150 hsm: migrate CA storage schema (#7245)
* hsm: migrate CA storage schema

Migrate types.CertAuthorityV2 schema according to
https://github.com/gravitational/teleport/blob/master/rfd/0025-hsm.md#backend-storage

Includes proto changes, types.CertAuthority wrapper changes and data
migration.

Note that we keep and update the old fields for backwards-compatibility.
If a cluster is upgraded to v7 and then downgraded back to v6,
everything should keep working.

* Address review feedback
2021-06-16 12:17:03 -05:00
NajiObeid 86a6abcfcb lazy init of prometheus collectors (#6561)
* lazy init of prometheus collectors

* incorporate metrics intorduced in #6271

* linting

* tests

* pr changes

* tests

* pr changes
2021-05-19 11:53:36 -04:00
jane quin 7c9fd8e50d Add additional Prometheus Metrics (#6511) 2021-04-28 15:46:27 -07:00
Steven Martin b9b170042d Misspelling (#6503) 2021-04-21 06:01:41 -07:00
Brian Joerger 2beb991598 API client connection overhaul (#5625)
* Added support for connecting API client through tunnel proxy and web proxy addresses (with identity file).

* Added concurrent dialing logic to dial several possible dialing combinations and seamlessly return the first client to connect.
2021-03-23 14:39:20 -07:00
Andrew Lytvynov 6d8f778157 mfa: add WithMFA to session-related audit events (#5833)
* mfa: put device UUID in MFAVerified cert extensions

Instead of just a bool, add the device UUID. This will be used in audit
events when a session is started using MFA-issued certs.

* Add WithMFA to session-related audit events

Also extract a common function for parsing SSH certs.
2021-03-04 14:18:30 -08:00
dmitri ae4e5bfc97 Remove args as these can be deduced automatically 2021-03-03 17:49:12 -08:00
dmitri ca87f92ed5 Use non-greedy Mkdir variant and add a test-case for non-existing remote location with intermediate directories 2021-03-03 17:49:12 -08:00
dmitri ea4adc8b7e Add more test coverage for sink mode 2021-03-03 17:49:12 -08:00
dmitri fb8c71c6fa Check whether . is a base directory directly 2021-03-03 17:49:12 -08:00
dmitri 007235446f Use correct target directory path.
Handle target directory/file renames.

Fixes https://github.com/gravitational/teleport/issues/5695.
2021-03-03 17:49:12 -08:00
Andrew Lytvynov fc1c1dbd14 Move all utils.InitLoggerForTests calls to TestMain
This prevents data races between changing the standard logger and it
acutally being used.
2021-02-23 18:04:55 -08:00
a-palchikov e65eac59b0 tsh scp to use target directory correctly (#5501)
* Fixes the scp logic to take target directory into account in sink mode.
Also expose channel error in scp client so the error is more visible to
the user. Old behavior will only output the 'exit code n' if anything
breaks.

Fixes https://github.com/gravitational/teleport/issues/5497.

* Silence 'wait: remote command exited without exit status or exit signal' error when interrupting the scp session. Leave a TODO to fix properly in a future PR

* Address review comments
2021-02-11 19:35:40 +01:00
Andrew Lytvynov 5ca68f2351 Remove 'var _ = fmt.Printf' from *_test.go files (#5438)
These declarations serve no purpose, likely leftover from old debugging.
2021-01-29 17:01:10 -08:00
Brian Joerger efe91c4def api dependency reduction - ssh (#5379)
Move Cert Authority methods out of api to remove dependency on crypto/ssh.
2021-01-29 10:28:24 -08:00
Brian Joerger 626ad243eb api dependency reduction - utils constants (#5363)
Moved constants and utils used in /api into /api/constants and /api/utils respectively.
2021-01-29 09:37:01 -08:00
a-palchikov 43d142085e Wait on scp process at the end of the test. Service the stderr pipe to (#5418)
avoid 'broken pipe' in scp side.

Fixes https://github.com/gravitational/teleport/issues/5417.
2021-01-28 12:55:54 +01:00
a-palchikov 0ddde38df2 Suppress linter warning about unnecessary type conversion on darwin. (#5302) 2021-01-14 19:23:48 +01:00
a-palchikov 524c9483b3 Explicitly cast time values to int64 to enable 32-bit builds. (#5291)
Updates https://github.com/gravitational/teleport/pull/4764.
2021-01-14 11:10:47 +01:00
a-palchikov 72630d1df5 Implement support for preserving file times for 'tsh scp' (#4764)
* Add -p flag to scp
* Add support for preserving access/modification times on files/directories when copying files between hosts.
* lib/sshutils/scp: add time statting for directories
* Add directory handling for scp
* Rewrite scp tests with testify
* Address review comments
2021-01-06 13:21:06 +01:00
a-palchikov c94e5042c7 Server data race (#4790)
* Add logger attributes to be able to propagate logger from tests for identifying tests
* Add test case for Server's DeepCopy.
* Update test to using the testing package directly. Update dependency after upstream PR.
2020-12-09 16:46:33 +01:00
a-palchikov 7c87576a8b flaky tests: consistent logging (#4849)
* Update logrus package to fix data races
* Introduce a logger that uses the test context to log the messages so they are output if a test fails for improved trouble-shooting.
* Revert introduction of test logger - simply leave logger configuration at debug level outputting to stderr during tests.
* Run integration test for e as well
* Use make with a cap and append to only copy the relevant roles.
* Address review comments
* Update integration test suite to use test-local logger that would only output logs iff a specific test has failed - no logs from other test cases will be output.
* Revert changes to InitLoggerForTests API
* Create a new logger instance when applying defaults or merging with file service configuration
* Introduce a local logger interface to be able to test file configuration merge.
* Fix kube integration tests w.r.t log
* Move goroutine profile dump into a separate func to handle parameters consistently for all invocations
2020-12-07 15:35:15 +01:00
Andrew Lytvynov 92ed2db38a Fixing golint warnings, batch 1
Mostly cosmetic changes:
- making receiver names consistent
- renaming `foo.FooBar` to `foo.Bar` (using package name as prefix)
- removing redundant `else` branches
- changing `a += 1` to `a++`
2020-10-13 00:22:49 +00:00
Forrest Marshall ae2336dfd0 concurrent session control
Adds support for Concurrent Session Control and a new
semaphore API.  Roles now support two new configuration
options, `max_ssh_connections` and `max_ssh_sessions`
which correspond to the total number of authenticated
ssh connections per cluster, and the number of ssh sessions
within a connection respectively.  Attempting to exceed
these limits generate variants of the `session.rejected`
audit event and cause the connection/session to be
rejected.
2020-09-17 11:02:35 -07:00
Joshua Behrens 19d482dad3 Allow user with at sign in name (#4002)
* Allow @ in scp targets
* Allow @ in proxyjump usernames
* Allow @ in tsh usernames
2020-07-21 10:41:31 -03:00
Andrew Lytvynov d3260103ff Keep using the default (ssh-rsa) signing algo for SSH handshakes
x/crypto/ssh does not support SHA2 signatures for handshakes yet. We'll
keep using SHA2 for cert signing, but handshakes have to wait.
2020-06-24 21:25:33 +00:00
Andrew Lytvynov a32ed8b118 Support RSA certificates in sshutuils.AlgSigner
Previously we matched the public key type for only plain public key
authn.
2020-06-24 21:25:33 +00:00
Andrew Lytvynov d7dc41659d Use CA signing alg from config file on manual rotation
This allows users to manually switch to a different algorithm by:
- setting the config file field
- running "tctl auth rotate"

If config file field is not set, existing signing algorithm of the CA is
preserved.
2020-06-24 21:25:33 +00:00
Andrew Lytvynov 9bc8fb3ae0 Add ca_signing_algo to the config file
This allows users to override the SHA2 signing algorithms we default to
now for compatibility with the (very) old OpenSSH versions.

For host and user certs, use the CA signing algo for their own
handshakes. This allows us to propagate the signing algo from auth
server everywhere else.
2020-06-24 21:25:33 +00:00
Andrew Lytvynov 96f56f3f40 Enforce SHA-512 for RSA SSH signatures
Motivation:

    x/crypto/ssh defaults to using SHA-1 for signatures:
    https://github.com/golang/crypto/blob/master/ssh/keys.go#L963-L982
    Because Teleport uses RSA for user, host and CA keys, we end up with
    SHA-1 by default.

    SHA-1 is now considered weak and OpenSSH plans to deprecate it:
    https://www.openssh.com/txt/release-8.3

Fix:

    Wrap all RSA `ssh.Signer`s and override `SignWithAlgorithm` to
    provide `SigAlgoRSASHA2512` if not otherwise specified. This will
    only affect new certs, existing certs will use `SigAlgoRSA` until
    rotated. For CA certs (e.g. exported with `tctl auth export`) users
    might need to manually rotate.

Limited local testing with openssh 8.2 client and
`-oHostKeyAlgorithms=-ssh-rsa` confirms that this works with a new
cluster and fails with an old one.
2020-06-24 21:25:33 +00:00
Forrest Marshall dfd40d21f5 proxy X11 forwarding support
- Role options now include a `permit_x11_forwarding` bool
which is set to `false` by default.

- Recording proxies now forward X11 requests and channels
when when permitted by RBAC.

- User certs will now include the `permit-X11-forwarding`
extension when permitted by RBAC.

- If X11 forwarding is requested for a session a new `x11`
audit event is emitted by recording proxies.
2020-06-24 11:40:47 -07:00
Forrest Marshall acde213069 Make agent channel setup lazy.
Changes agent channel setup behavior to be consistent
openssh by having servers lazily request agent channels
when they are needed, rather than immediately starting a
single connection-wide channel as soon as forwarding is
requested.  Fixes an issue introduced in #3613 which
caused openssh clients to hang on exit due to persistent
agent channel.
2020-06-10 14:15:51 -07:00
Andrew Lytvynov e6aab1dcaa errcheck: add missing error logging in lib/srv 2020-06-01 17:00:07 +00:00
Andrew Lytvynov f20da0caca Fix data races when accessing internal listeners
These listeners are already protected elsewhere, just missing locking in
a couple methods.
2020-05-21 20:38:37 +00:00
Andrew Lytvynov e2d65a3156 Auto assign ports for lib/srv/regular tests 2020-05-21 20:38:37 +00:00
Andrew Lytvynov d52ca0617d Add missing error checks in lib/srv and lib/sshutils
There's many more left in lib/srv, but this change is already big.
Some errors are left unhandled, where it makes sense.
2020-05-15 16:56:44 +00:00