Commit Graph
867 Commits
Author SHA1 Message Date
Alan Parra 5a11006f81 Add ReadPassword functionality to ContextReader (#11436)
This changes prompt.ContextReader in the following ways:

Reads only happen as a response to Read methods being called. This allows
ContextReader to coexist with other readers as long as no reads are abandoned.
ReadPassword is now available, the underlying implementation being
term.ReadPassword. An abandoned password read may be turned into a clean read.
This gives us some UX flexibility when callers abandon password reads (looking
at you, PromptMFAChallenge). Turning clean reads into password reads is not
supported. It's tricky and I have a few ideas, but it's not paramount at this
moment.

This solves the woes caused by abandoned OTP reads followed by PIN reads in
different packages, such as client.PromptMFAChallenge followed by tsh mfa add's
implementation.

#9160

* Move ContextReader to its own file
* Refactor ContextReader and implement ReadPassword
* Test ReadPassword
* Fix typos
* Remove prompt.StdinSync()

prompt.Stdin() has the same behavior for non-abandoned reads.

* Group /x/term methods under a type
2022-03-25 17:17:20 +00:00
Joel 445d40d8a8 Sort sessions by creation date (#11345) 2022-03-24 12:58:49 +00:00
STeve (Xin) Huang 3d7de736e3 Improve cli usage when command name is long (#10981) 2022-03-23 19:08:42 +00:00
Alan Parra b2c5c8ecb0 Add FIDO2 passwordless login and registration to tsh (#11321)
Passwordless login is enabled by the global `--pwdless` flag. Registration gets
a new prompt and an `--allow-passwordless` flag.

UX messages were tweaked to follow the descriptions on RFD 53: Passwordless
FIDO2[1].

Passwordless login requires two touches for all devices (both PIN and biometric).
I'd like to get it down to a single touch, at least for the most common
situations, but that'll be a follow up to this work.

Passwordless support requires `tsh` to be compiled with the `libfido2` tag, try
`go build -tags=libfido2 ./tool/tsh`.

#9160

[1] https://github.com/gravitational/teleport/blob/master/rfd/0053-passwordless-fido2.md#ux

* Allow reuse of devices for passwordless
* Implement passwordless registration in tsh
* Add better tracing to FIDO2 filters
* Implement passwordless logins in tsh
* Make --pwdless a global flag
* Fix lint errors
* Fix U2F tests
* Use initClient's URL as origin
* Distinguish whether --allow-passwordless is set or unset
2022-03-23 18:38:10 +00:00
Alex McGrath 3d35263a6c Add a .tsh/config file and add support for configuring custom http headers 2022-03-23 14:19:07 +00:00
Tim Buckley b70c1d6d63 Add a note to tctl/main.go about updating tctl Enterprise. (#11168) 2022-03-22 23:36:36 +00:00
Zac Bergquist 55cbd0ac97 Remove use of deprecated ioutil package (#11296)
* Remove use of deprecated ioutil package
* Add lint rule to check for ioutil imports
2022-03-21 18:00:34 +00:00
Krzysztof Skrzętnicki 82bcbc4b60 Show usage on invalid command line invocation. (#11174) 2022-03-21 17:31:31 +00:00
Zac Bergquist c9c35a1791 Update descriptions in our --help messages (#11267) 2022-03-21 15:28:16 +00:00
Alan Parra 023f533be2 Wire FIDO2 into tsh login and registration (#11241)
Seamlessly change the public API of lib/auth/webauthncli to use the
libfido2-backed implementation, as long as the binary was compiled with the
libfido2 build tag.

A few adjustments are necessary to "wancli" methods to allow users to provide
prompt callbacks and to return the credential user (not applicable here, but
will be in following PRs).

Additional changes are made to tsh mfa add in order to avoid stdin hijacking by
ContextReader, since we now may require PIN reads for authenticators.

#9160

* Move U2F logic to u2f_* files
* Split U2F API from general l/a/webauthncli API
* Move FIDO2 public API to fido2_common.go, introduce IsFIDO2Available
* Introduce prompt.SyncReader

Sync reads allow prompt calls to be mixed with term.ReadPassword calls.

* Wire FIDO2 into MFA login
* Wire FIDO2 into MFA registration
2022-03-21 14:35:08 +00:00
Russell JonesandPaul Gottschling 70474d9871 Added Machine ID CLI and configuration references.
Added Machine ID CLI and configuration references.

Co-authored-by: Paul Gottschling <paul.gottschling@goteleport.com>
2022-03-18 14:19:58 -07:00
Edoardo Spadolini 160df0086a Support role bootstrapping in OSS (#11175)
* Add role bootstrapping

* Test coverage

* Better variable names

* Remove spurious log, add better error messages
2022-03-17 10:12:18 +00:00
Jakub Nyckowski 1ab20d6631 Improve tsh error message if mysql client is missing (#11204) 2022-03-17 00:50:37 +00:00
Tim Buckley dba79e8c7e Fix improper default value check in tbot's FromCLIConf() (#11169)
The default `join_method` value was improperly assumed to be "" which
caused any onboarding config from the config file to be overwritten.

This uses the correct default and allows bots to be fully onboarded
via config file.

Fixes #11099
2022-03-16 21:46:19 +00:00
Tim Buckley 254f89f2ff Fix outdated CLI help for tbot init --owner (#11158)
The inferred default was changed without updating the flag's help
message. This updates the help message to explain the new default
value of `--owner`.
2022-03-15 21:55:31 +00:00
Zac Bergquist 74bc1fbed9 Remove mention of max ttl for tctl tokens command (#11148)
The 48h maximum is enforced for `tctl users add`,
not `tctl tokens add`.

Fixes #11137
2022-03-15 20:46:10 +00:00
Alex McGrath 40200e8536 Reslove comments, move all occurences of teleport.dev to use a constant 2022-03-15 13:22:45 +00:00
Alex McGrath a4c94e4637 Add configurable verbosity to tctl get roles 2022-03-15 13:22:45 +00:00
Alex McGrath 19270c1e71 Resolve comments 2022-03-15 13:22:45 +00:00
Alex McGrath b6df9a742a Add verbosity to tctl * ls commands and resource get. 2022-03-15 13:22:45 +00:00
Alex McGrath ad41b3c154 Move 'MakeTableWithTruncatedColumn' to asciitable and truncate labels 2022-03-15 13:22:45 +00:00
Alex McGrath cdae4e3ee2 ls consistency: add support for tctl desktop ls
```
Host Public Address       AD Domain   Labels               Version
---- -------------------- ----------- -------------------- ---------
corn 192.168.122.144:3389 example.com teleport..3 (9       9.0.0-dev
corn 192.168.122.51:3389  example.com teleport.rd Evle.com 9.0.0-dev
```

```yaml
kind: windows_desktop
metadata:
  expires: "2022-02-18T16:12:52.422659238Z"
  id: 1645200172423989197
  labels:
    teleport.dev/computer_name: WIN-LA2V0OD7SK0
    teleport.dev/dns_host_name: WIN-LA2V0OD7SK0.example.com
    teleport.dev/is_domain_controller: "true"
    teleport.dev/origin: dynamic
    teleport.dev/os: Windows Server 2012 R2 Standard Evaluation
    teleport.dev/os_version: 6.3 (9600)
    teleport.dev/windows_domain: example.com
  name: WIN-LA2V0OD7SK0-example-com
spec:
  addr: 192.168.122.51:3389
  domain: example.com
  host_id: 2c807641-92ae-4c70-88fe-b93e7b0aa179
version: v3
```
2022-03-15 13:22:45 +00:00
Alex McGrath 1627d79275 ls consistency: add tctl kube ls command
```
Cluster     Labels Version
----------- ------ -------------
minikube           8.0.0-alpha.1
honkcluster        8.0.3
```

```yaml
kind: kube_service
metadata:
  expires: "2021-12-16T16:07:14.898611765Z"
  id: 1639670234899200604
  name: 7b3ca8d8-710c-4305-aa29-e73628ac572c
spec:
  addr: 127.0.0.1:3027
  hostname: ""
  kube_clusters:
  - name: minikube
  rotation:
    current_id: ""
    last_rotated: "0001-01-01T00:00:00Z"
    schedule:
      standby: "0001-01-01T00:00:00Z"
      update_clients: "0001-01-01T00:00:00Z"
      update_servers: "0001-01-01T00:00:00Z"
    started: "0001-01-01T00:00:00Z"
  version: 8.0.0-alpha.1
version: v2
---
kind: kube_service
metadata:
  expires: "2021-12-16T16:10:13.068855399Z"
  id: 1639670413069866294
  name: 9153a5a9-e85e-4972-8c50-6fa8923282b2
spec:
  addr: remote.kube.proxy.teleport.cluster.local
  hostname: ""
  kube_clusters:
  - name: honkcluster
  rotation:
    current_id: ""
    last_rotated: "0001-01-01T00:00:00Z"
    schedule:
      standby: "0001-01-01T00:00:00Z"
      update_clients: "0001-01-01T00:00:00Z"
      update_servers: "0001-01-01T00:00:00Z"
    started: "0001-01-01T00:00:00Z"
  version: 8.0.3
version: v2
```yaml
2022-03-15 13:22:45 +00:00
Alex McGrath 5fcc19789f ls consistency: make tctl db ls output consistent
```
Host Name     Protocol URI          Labels                          Version
---- -------- -------- ------------ ------------------------------- -------------
corn postgres postgres 0.0.0.0:5432 teleport.dev/origin=config-file 8.0.0-alpha.1
```
2022-03-15 13:22:45 +00:00
Alex McGrath cff5165ad3 ls consistency: make tctl apps ls output consistent
```
Host Name        Public Address       URI                 Labels                          Version
---- ----------- -------------------- ------------------- ------------------------------- -------------
corn example-app example-app.corn.lan http://0.0.0.0:8000 teleport.dev/origin=config-file 8.0.0-alpha.1
```
2022-03-15 13:22:45 +00:00
Alex McGrath 23731673d9 ls consistency: Make tctl nodes ls output consistent, support yaml
New format:
```
Host UUID                                 Public Address Labels                    Version
---- ------------------------------------ -------------- ------------------------- -------------
corn 7b3ca8d8-710c-4305-aa29-e73628ac572c 127.0.0.1:3022 env=example,hostname=corn 8.0.0-alpha.1
```

With `--yaml`
```yaml
kind: node
metadata:
  expires: "2021-12-16T15:26:44.887862347Z"
  id: 1639667804888460055
  labels:
    env: example
  name: 7b3ca8d8-710c-4305-aa29-e73628ac572c
spec:
  addr: 127.0.0.1:3022
  cmd_labels:
    hostname:
      command:
      - hostname
      period: 1m0s
      result: corn
  hostname: corn
  public_addr: corn.lan:8443
  rotation:
    current_id: ""
    last_rotated: "0001-01-01T00:00:00Z"
    schedule:
      standby: "0001-01-01T00:00:00Z"
      update_clients: "0001-01-01T00:00:00Z"
      update_servers: "0001-01-01T00:00:00Z"
    started: "0001-01-01T00:00:00Z"
  version: 8.0.0-alpha.1
version: v2
```
2022-03-15 13:22:45 +00:00
Alex McGrath 39977efc00 Add tests for motd fixes
Part of this includes renaming export_test.go to export.go so I could
test the MOTD outside of lib/client/export.go
2022-03-15 12:18:39 +00:00
Alex McGrath de9bdf086d Fix MOTD not showing up on tsh login with certain arguments
- changes to configuration.go: fixes tsh login in first test case
  `tsh login --insecure --proxy=127.0.0.1:3080 --user=test`
- changes to apiserver.go fixes `--auth` not showing motd
2022-03-15 12:18:39 +00:00
Tim Buckley 9769698daf Silence false positive lints from staticcheck in tbot/init.go (#11084)
`staticcheck` does not seem to appreciate our nop implementations for
non-Linux OSes and produces several noisy warnings about it. This
disables the lints as precisely as possible.
2022-03-14 16:55:22 +00:00
Lisa Kim 628564c801 Update 'tctl apps/db/nodes ls' to accept filter flags (#11003) 2022-03-11 17:57:40 +00:00
Joel 92543d9b3e Moderated Sessions improvements (#10991) 2022-03-10 23:04:12 +00:00
bea5f7fde4 UX improvements for tbot (#10833)
* UX improvements for tbot

A last batch of UX tweaks for 9.0:
 - rename --renew-interval -> renewal-interval
 - add `--oneshot` mode to fetch one set of certs and exit (client
   side only, no server enforcement yet)
 - add `tbot version`
 - add unix signal handling: graceful exit on SIGINT, reload on
   SIGHUP/SIGUSR1
 - make auth server an optional config option and check it only when
   needed (i.e. `tbot start`)

* Remove `--auth-server` flag from `tbot init` example

* Add `cut` workaround to allow connecting to nodes without DNS

* Update product name in tbot CLI help

* Add `--format=json` support to `tctl bots add`

* Detect OpenSSH version and conditionally remove the RSA deprecation workaround

* Fix failing unit test after rename

* Update tool/tbot/config/configtemplate_ssh.go

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* Address review feedback

* Apply suggestions from code review

Co-authored-by: Alan Parra <alan.parra@goteleport.com>

* Document IncludeRSAWorkaround and address review comments

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>
Co-authored-by: Alan Parra <alan.parra@goteleport.com>
2022-03-10 20:41:10 +00:00
rosstimothy 550d23d15d Fix goroutine and memory leak in watchCertAuthorities (#10871)
* Fix goroutine and memory leak in watchCertAuthorities

The CA Watcher was blocking both on writing to a channel when the watcher
was closed and on HTTP calls that had no request timeout or context passed
to cause cancellation.

All resourceWatcher implementations that had a bug which may cause them to block
on writing to a channel forever were fixed by selecting on the write and ctx.Done.

Adding context.Context to all Get/Put/Post/Delete methods on the auth HTTPClient to
force callers to propagate context. Prior all calls used context.TODO which
prevents requests from being properly cancelled.

Add context propagation to RotateCertAuthority, RotateExternalCertAuthority,
GetCertAuthority, GetCertAuthorities. This is needed to get the correct ctx
from the CertAtuhorityWatcher all the way down to the HTTPClient that makes
the call.

Closes #10648
2022-03-10 11:05:39 -05:00
32e48017d3 Implement tbot init subcommand and ACL management (#10289)
* Add certificate renewal bot

This adds a new `tbot` tool to continuously renew a set of
certificates after registering with a Teleport cluster using a
similar process to standard node joining.

This makes some modifications to user certificate generation to allow
for certificates that can be renewed beyond their original TTL, and
exposes new gRPC endpoints:
 * `CreateBotJoinToken` creates a join token for a bot user
 * `GenerateInitialRenewableUserCerts` exchanges a token for a set of
   certificates with a new `renewable` flag set

A new `tctl` command, `tctl bots add`, creates a bot user and calls
`CreateBotJoinToken` to issue a token. A bot instance can then be
started using a provided command.

* Cert bot refactoring pass

* Use role requests to split renewable certs from end-user certs
* Add bot configuration file
* Use `teleport.dev/bot` label
* Remove `impersonator` flag on initial bot certs
* Remove unnecessary `renew` package
* Misc other cleanup

* Do not pass through `renewable` flag when role requests are set

This adds additional restrictions on when a certificate's `renewable`
flag is carried over to a new certificate. In particular, it now also
denies the flag when either role requests are present, or the
`disallowReissue` flag has been previously set.

In practice `disallow-reissue` would have prevented any undesired
behavior but this improves consistency and resolves a TODO.

* Various tbot UX improvements; render SSH config

* Fully flesh out config template rendering
* Fix rendering for SSH configuration templates
* Added `String()` impls for destination types
* Improve certificate renewal logging; show more detail
* Properly fall back to default (all) roles
* Add mode hints for files
* Add/update copyright headers

* Add stubs for tbot init and watch commands

* Add gRPC endpoints for managing bots

* Add `CreateBot`, `DeleteBot`, and `GetBotUsers` gRPC endpoints
* Replace `tctl bot (add|rm|ls)` implementations with gRPC calls
* Define a few new constants, `DefaultBotJoinTTL`, `BotLabel`,
  `BotGenerationLabel`

* Fix outdated destination flag in example tbot command

* Bugfix pass for demo

* Fixed a few nil pointer derefs when using config from CLI args
* Properly create destination if `--destination-dir` flag is used
* Remove improper default on CLI flag
* `DestinationConfig` is now a list of pointers

* Address first wave of review feedback

Fixes the majority of smaller issues caught by reviewers, thanks all!

* Add doc comments for bot.go functions

* Return the token TTL from CreateBot

* Split initial user cert issuance from `generateUserCerts()`

Issuing initial renewable certificate ended up requiring a lot of
hacks to skip checks that prevented anonymous bots from getting
certs even though we'd verified their identity elsewhere (via token).

This reverts all those hacks and splits initial bot cert logic into a
dedicated `generateInitialRenewableUserCerts()` function which should
make the whole process much easier to follow.

* Set bot traits to silence log messages

* tbot log message consistency pass

* Implement `tbot init` subcommand

This adds a new CLI subcommand to initialize a tbot destination
directory by creating required files ahead of time and assigning
proper permissions (and ACLs, where possible).

* Resolve lints

* Add config tests

* Remove CreateBotJoinToken endpoint

Users should instead use the CreateBot/DeleteBot endpoints.

* Create a fresh private key for every impersonated identity renewal

* Hide `config` subcommand

* Rename bot label prefix to `teleport.internal/`

* Use types.NewRole() to create bot roles

* Clean up error handling in custom YAML unmarshallers

Also, add notes about the supported YAML shapes.

* Fetch proxy host via gRPC Ping() instead of GetProxies()

* Update lib/auth/bot.go

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* Fix some review comments

* Add renewable certificate generation checks (#10098)

* Add renewable certificate generation checks

This adds a new validation check for renewable certificates that
maintains a renewal counter as both a certificate extension and a
user label. This counter is used to ensure only a single certificate
lineage can exist: for example, if a renewable certificate is stolen,
only one copy of the certificate can be renewed as the generation
counter will not match

When renewing a certificate, first the generation counter presented
by the user (via their TLS identity) is compared to a value stored
with the associated user (in a new `teleport.dev/bot-generation`
label field). If they aren't equal, the renewal attempt fails.
Otherwise, the generation counter is incremented by 1, stored to the
database using a `CompareAndSwap()` to ensure atomicity, and set on
the generated certificate for use in future renewals.

* Add unit tests for the generation counter

This adds new unit tests to exercise the generation counter checks.

Additionally, it fixes two other renewable cert tests that were
failing.

* Remove certRequestGeneration() function

* Emit audit event when cert generations don't match

* Fully implement `tctl bots lock`

* Show bot name in `tctl bots ls`

* Lock bots when a cert generation mismatch is found

* Make CompareFailed respones from validateGenerationLabel() more actionable

* Update lib/services/local/users.go

Co-authored-by: Nic Klaassen <nic@goteleport.com>

* Backend changes for tbot IoT and AWS joining (#10360)

* backend changes

* add token permission check

* pass ctx from caller

Co-authored-by: Roman Tkachenko <roman@goteleport.com>

* fix comment typo

Co-authored-by: Roman Tkachenko <roman@goteleport.com>

* use UserMetadata instead of Identity in RenewableCertificateGenerationMismatch event

* Client changes for tbot IoT joining (#10397)

* client changes

* delete replaced APIs

* delete unused tbot/auth.go

* add license header

* don't unecessarily fetch host CA

* log fixes

* s/tunnelling/tunneling/

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* auth server addresses may be proxies

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* comment typo fix

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* move *Server methods out of auth_with_roles.go (#10416)

Co-authored-by: Tim Buckley <tim@goteleport.com>

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>
Co-authored-by: Tim Buckley <tim@goteleport.com>

Co-authored-by: Roman Tkachenko <roman@goteleport.com>
Co-authored-by: Tim Buckley <tim@goteleport.com>
Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

Co-authored-by: Nic Klaassen <nic@goteleport.com>
Co-authored-by: Roman Tkachenko <roman@goteleport.com>
Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* Address another batch of review feedback

* Addres another batch of review feedback

Add `Role.SetMetadata()`, simplify more `trace.WrapWithMessage()`
calls, clear some TODOs and lints, and address other misc feedback
items.

* Fix lint

* Add missing doc comments to SaveIdentity / LoadIdentity

* Remove pam tag from tbot build

* Update note about bot lock deletion

* Another pass of review feedback

Ensure all requestable roles exist when creating a bot, adjust the
default renewable cert TTL down to 1 hour, and check types during
`CompareAndSwapUser()`

* Remove ModeHint

* Rename Identity.Cert and Identity.XCert

* Add `symlinks` flag to tbot config

The optional symlinks flag for directory destinations allows users to
opt in / out of whichever symlink attack hardening mode is selected
by default.

* Add mostly-working secure implementation of botfs.Create/Write

This adds symlink mode selection (secure, try-secure, insecure) and
Linux `Create()`/`Write()` implementations to open files safely.

* Add configurable ACL modes and verify ACL support in tbot init

* Initialize destinations at startup and test before renewal

This initializes destinations at startup (to create directories if
not using `tbot init`) and tests them to ensure the bot can write
_before_ attempting to renew certificates; this should prevent most
accidental generation counter locks.

* Hide watch for now

* Issue a new identity if a token change is detected

* Warn if identity appears to be expired on startup

* Fully implement ACL Verify and Configure

 - Fully implements ACL support for Linux
 - Adds bot-side verification support to ensure ACLs are configured
   properly at runtime.
 - Gracefully falls back to no ACLs if the platform / filesystem
   doesn't support them
 - Clear up outstanding lints

* Make `tbot init` work without a config file

* Show init instructions in tctl bots add

Also:
 - Make --bot-user a flag in init (the tctl instructions were
   confusing otherwise)
 - Handle IsOwnedBy sanely on unsupported platforms
 - Add Bold colorizing support

* Clear some TODOs and rephrase tctl help

* Fix typo

* Fix token hash detection bug

* Actually read and write certs with symlink enforcement

Also, fix a config loading bug where CheckAndSetDefaults() wasn't
being called in all cases with CLI destinations.

* Add workaround for OpenSSH permissions check with ACLs

OpenSSH has an overly-paranoid permissions check that forces key
files to be exclusively owner-readable. Unfortunately, for POSIX
compatibility purposes, when ACLs are set, the ACL mask is set as
the group permissions. This effectively makes any ACL incompatible
with OpenSSH.

However, OpenSSH's check does have an escape hatch: it only applies
if the current user is the owner of the file. Therefore, this change
tweaks the `tbot init` flow to create files as root, owned by a
separate user (either `nobody` or even the bot user), with ACL
permissions granting both the bot and reader user access to the
certificates. This effectively bypasses OpenSSH's permissions check
and should preserve our security boundaries.

* Fix lints

* Fix an improper directory chmod to 0600 if ACL test fails

* First pass of tbot init unit tests

* Add symlink tests and fix bug with resolving the default owner

* Fix err misuse

* Fix an ACL error if the bot or reader user is the owner.

* Fix typo

* Fix missing error case in VerifyACL causing unreadable directories

* Address review feedback

- Rename ACLOn -> ACLRequired
- Simplify fs_linux.Read()
- Add missing fs_other.Read()
- Hoist renewal loop logic into its own function
- A few misc bugfixes

* Apply suggestions from code review

Co-authored-by: rosstimothy <39066650+rosstimothy@users.noreply.github.com>

* Address review feedback

- Only log syscall warning once
- Formatting and wording changes
- Improve error handling for `--clean`

* Fix lint error

* Fix imports in fs_other

* Fix possible nil pointer deref if storage is unset

* Use the bot user as default owner

This is more likely to be a safe owner choice than `nobody:nobody`.

* Apply suggestions from code review

Co-authored-by: Roman Tkachenko <roman@goteleport.com>

* Code review fixes

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>
Co-authored-by: Nic Klaassen <nic@goteleport.com>
Co-authored-by: Roman Tkachenko <roman@goteleport.com>
Co-authored-by: rosstimothy <39066650+rosstimothy@users.noreply.github.com>
2022-03-10 06:09:01 +00:00
Lisa Kim 350ea5bb95 Updates tsh ls for node/app/db/kube to accept new filter flags (#10980)
* Also adds a search keyword parser that takes in different
  delimiters (comma is used for tsh, space is used for web UI)

part of RFD 55
2022-03-09 23:56:55 +00:00
Brian Joerger 600022b290 Change NewRole to use V5 by default, old consumers now user NewRoleV3. (#10884) 2022-03-08 21:11:53 +00:00
Vitor Enes f314e59ad2 Default to https scheme for --proxy argument in tctl auth sign (#10844)
Before this commit, if `--proxy` was set, it would be passed as it to the kubeconfig file. Due to this, if the `--proxy` URL did not have a scheme, it would default to `http`,  leading to the issue reported in https://github.com/gravitational/cloud/issues/1358.

With this commit, we now try to parse the `--proxy` URL and set its scheme to `https` in case it's not set.
In case it's set, we only allow `--proxy` URLs with the `http` and `https` schemes.
2022-03-07 10:04:53 +00:00
Edoardo Spadolini 8983ededb4 Leaf cluster CA sanitizing (#10741)
* Enforce that a leaf cluster has sent us just a single host CA

* Test coverage for validateTrustedCluster

* Add `tctl rm cert_authority/kind/name`

* Check against existing trusted clusters
2022-03-03 11:46:19 +00:00
Matheus fe519a3211 Add proxy to instructions when creating a token for a node (#9539)
* Print proxy instead of auth server on join node instructions for Cloud instances
2022-03-02 10:20:35 -03:00
Nic Klaassen 6e16ad6627 IAM join method support for tbot (#10535) 2022-03-01 00:35:34 +00:00
Jakub Nyckowski 75e24cbd54 Display correct error message when host is missing in tctl auth sign (#10588) 2022-02-28 15:22:51 -05:00
Alan Parra bac0ccdc99 Remove U2F support (#10476)
Follows up on #10466 by removing remaining U2F references, including proto/gRPC
surface and the lib/auth/u2f package itself.

#10375

* Remove U2F from lib/auth/ (1)
* Remove U2F from lib/auth/ (2)
* Remove U2F from lib/auth/ (3)
* Remove U2F from lib/services/
* Remove U2F from tsh mfa add suggestions
* Remove U2F protos
* Update generated protos
* Cleanup a few stragglers
* Remove lib/auth/u2f package
* Fix references to auth.MFAAuthenticateChallenge
* Revert needless lib/auth/password.go change
* Update e/ to ad8fd4a (U2F cleanup)
* Fix stragglers from latest master rebase
* Fix lint and compile failures
2022-02-24 19:54:28 +00:00
Logan Davis 0602d7661f Adds application proxy to tsh (#10509) 2022-02-23 20:29:54 -06:00
bb121d7b1e Certificate renewal bot (#10099)
* Add certificate renewal bot

This adds a new `tbot` tool to continuously renew a set of
certificates after registering with a Teleport cluster using a
similar process to standard node joining.

This makes some modifications to user certificate generation to allow
for certificates that can be renewed beyond their original TTL, and
exposes new gRPC endpoints:
 * `CreateBotJoinToken` creates a join token for a bot user
 * `GenerateInitialRenewableUserCerts` exchanges a token for a set of
   certificates with a new `renewable` flag set

A new `tctl` command, `tctl bots add`, creates a bot user and calls
`CreateBotJoinToken` to issue a token. A bot instance can then be
started using a provided command.

* Cert bot refactoring pass

* Use role requests to split renewable certs from end-user certs
* Add bot configuration file
* Use `teleport.dev/bot` label
* Remove `impersonator` flag on initial bot certs
* Remove unnecessary `renew` package
* Misc other cleanup

* Do not pass through `renewable` flag when role requests are set

This adds additional restrictions on when a certificate's `renewable`
flag is carried over to a new certificate. In particular, it now also
denies the flag when either role requests are present, or the
`disallowReissue` flag has been previously set.

In practice `disallow-reissue` would have prevented any undesired
behavior but this improves consistency and resolves a TODO.

* Various tbot UX improvements; render SSH config

* Fully flesh out config template rendering
* Fix rendering for SSH configuration templates
* Added `String()` impls for destination types
* Improve certificate renewal logging; show more detail
* Properly fall back to default (all) roles
* Add mode hints for files
* Add/update copyright headers

* Add stubs for tbot init and watch commands

* Add gRPC endpoints for managing bots

* Add `CreateBot`, `DeleteBot`, and `GetBotUsers` gRPC endpoints
* Replace `tctl bot (add|rm|ls)` implementations with gRPC calls
* Define a few new constants, `DefaultBotJoinTTL`, `BotLabel`,
  `BotGenerationLabel`

* Fix outdated destination flag in example tbot command

* Bugfix pass for demo

* Fixed a few nil pointer derefs when using config from CLI args
* Properly create destination if `--destination-dir` flag is used
* Remove improper default on CLI flag
* `DestinationConfig` is now a list of pointers

* Address first wave of review feedback

Fixes the majority of smaller issues caught by reviewers, thanks all!

* Add doc comments for bot.go functions

* Return the token TTL from CreateBot

* Split initial user cert issuance from `generateUserCerts()`

Issuing initial renewable certificate ended up requiring a lot of
hacks to skip checks that prevented anonymous bots from getting
certs even though we'd verified their identity elsewhere (via token).

This reverts all those hacks and splits initial bot cert logic into a
dedicated `generateInitialRenewableUserCerts()` function which should
make the whole process much easier to follow.

* Set bot traits to silence log messages

* tbot log message consistency pass

* Resolve lints

* Add config tests

* Remove CreateBotJoinToken endpoint

Users should instead use the CreateBot/DeleteBot endpoints.

* Create a fresh private key for every impersonated identity renewal

* Hide `config` subcommand

* Rename bot label prefix to `teleport.internal/`

* Use types.NewRole() to create bot roles

* Clean up error handling in custom YAML unmarshallers

Also, add notes about the supported YAML shapes.

* Fetch proxy host via gRPC Ping() instead of GetProxies()

* Update lib/auth/bot.go

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* Fix some review comments

* Add renewable certificate generation checks (#10098)

* Add renewable certificate generation checks

This adds a new validation check for renewable certificates that
maintains a renewal counter as both a certificate extension and a
user label. This counter is used to ensure only a single certificate
lineage can exist: for example, if a renewable certificate is stolen,
only one copy of the certificate can be renewed as the generation
counter will not match

When renewing a certificate, first the generation counter presented
by the user (via their TLS identity) is compared to a value stored
with the associated user (in a new `teleport.dev/bot-generation`
label field). If they aren't equal, the renewal attempt fails.
Otherwise, the generation counter is incremented by 1, stored to the
database using a `CompareAndSwap()` to ensure atomicity, and set on
the generated certificate for use in future renewals.

* Add unit tests for the generation counter

This adds new unit tests to exercise the generation counter checks.

Additionally, it fixes two other renewable cert tests that were
failing.

* Remove certRequestGeneration() function

* Emit audit event when cert generations don't match

* Fully implement `tctl bots lock`

* Show bot name in `tctl bots ls`

* Lock bots when a cert generation mismatch is found

* Make CompareFailed respones from validateGenerationLabel() more actionable

* Update lib/services/local/users.go

Co-authored-by: Nic Klaassen <nic@goteleport.com>

* Backend changes for tbot IoT and AWS joining (#10360)

* backend changes

* add token permission check

* pass ctx from caller

Co-authored-by: Roman Tkachenko <roman@goteleport.com>

* fix comment typo

Co-authored-by: Roman Tkachenko <roman@goteleport.com>

* use UserMetadata instead of Identity in RenewableCertificateGenerationMismatch event

* Client changes for tbot IoT joining (#10397)

* client changes

* delete replaced APIs

* delete unused tbot/auth.go

* add license header

* don't unecessarily fetch host CA

* log fixes

* s/tunnelling/tunneling/

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* auth server addresses may be proxies

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* comment typo fix

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* move *Server methods out of auth_with_roles.go (#10416)

Co-authored-by: Tim Buckley <tim@goteleport.com>

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>
Co-authored-by: Tim Buckley <tim@goteleport.com>

Co-authored-by: Roman Tkachenko <roman@goteleport.com>
Co-authored-by: Tim Buckley <tim@goteleport.com>
Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

Co-authored-by: Nic Klaassen <nic@goteleport.com>
Co-authored-by: Roman Tkachenko <roman@goteleport.com>
Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>

* Address another batch of review feedback

* Addres another batch of review feedback

Add `Role.SetMetadata()`, simplify more `trace.WrapWithMessage()`
calls, clear some TODOs and lints, and address other misc feedback
items.

* Fix lint

* Add missing doc comments to SaveIdentity / LoadIdentity

* Remove pam tag from tbot build

* Update note about bot lock deletion

* Another pass of review feedback

Ensure all requestable roles exist when creating a bot, adjust the
default renewable cert TTL down to 1 hour, and check types during
`CompareAndSwapUser()`

Co-authored-by: Zac Bergquist <zmb3@users.noreply.github.com>
Co-authored-by: Nic Klaassen <nic@goteleport.com>
Co-authored-by: Roman Tkachenko <roman@goteleport.com>
2022-02-19 02:41:45 +00:00
Gabriel Corado df44457b02 feat: aws database configurator (#9145) 2022-02-18 21:15:54 +00:00
Alex McGrathandZac Bergquist 611c05106f Add support for windows desktop services proxying different desktops (#10101)
* Add support for windows desktop services proxying different desktops

* Add filter to GetWindowsDesktops, remove GetWindowsDesktop and GetWindowsDesktopByName

* Cache cleanup

* Fix cache deletes for Windows desktops

For deletes, the cache only gets the backend key, not the entire
resource. Do what database access does, which is to extract the
host ID from the path, and stuff it in the description field of
the resource header.

* Godoc cleanup

* Fix lint

* Address review comments

* Send error message if no desktop found

* Revert to x/net/websocket

This got converted to gorilla/websocket as part of moderated sessions.
We'll do a more intentional conversion post-release.

* fix lint

Co-authored-by: Zac Bergquist <zac.bergquist@goteleport.com>
2022-02-18 00:01:08 +00:00
Roman Tkachenko 41899806fd Add SQL Server support for database access (#10097) 2022-02-17 02:20:33 +00:00
Brian Joerger eeef122954 Check for shell user's home directory as that user (#10321) 2022-02-16 23:51:02 +00:00
Jakub Nyckowski 530ff4c402 Add Redis integration (#10053)
Add support for Database Access for Redis for standalone and cluster self-hosted instances. Teleport requires mTLS in order to connect to Redis instance which is only supported in Redis 6.0+. RESP2 is currently the only supported protocol.
2022-02-16 13:32:32 -05:00
Joel ea810d30d9 Implement Moderated Sessions (#8563)
* Implement Moderated Sessions
2022-02-15 17:02:10 +01:00