mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
* PIV authentication for RDP This uncomfortably large change fully implements smartcard PIV authentication for RDP clients using the Teleport CA: - PIV applet implementation in emulated RDP smartcard - generating Windows-compatible certificates using Teleport CA with a dedicated RPC - generating dummy CRLs for Teleport CA and publishing it via LDAP The CRLs are required by Windows for any smartcard login certificate, we can't avoid that. But we can avoid making it public: the CRL can live in ActiveDirectory instead of a public endpoint of a Teleport service. Here, we use LDAP to publish the CRL on startup, valid for a year. There are a few unhandled cases in the current implementation: - LDAP server certificate is not validated when upgrading to TLS - multiple active CAs (with HSMs) are not supported, only one CRL is published - CA rotation is not supported, CRL is not re-published on rotation All of the above issues will be handled in future PRs as this one is already too large. * Address review feedback * Fix linter errors
This package is documented using a combination of pkg.go.dev and Teleport Docs.