Files
teleport/lib/join/boundkeypair
Tim Buckley 91caa689fe Enforce join token locks for agents (#65818)
* Enforce join token locks for agents

When agents attempt to join with the the bound keypair join method
and fail join state verification, a lock is created. This lock
traditionally targeted only bots.

While the lock target - the join token - is ostensibly not bot
specific, we were not plumbing through the token name into host
certificates, meaning the lock wasn't practically enforced for
host identities. Future join attempts would still fail, but the
existing agents wouldn't be locked.

This change adds a test for agent locking, plumbs through the
join token name in host certificates, and updates the lock message
text for agents so it isn't bot specific.

Note that agents do not have an analogous notion of renewable
identities and don't have a generation counter - their identities
last 10 years and don't renew. This means bound keypair agents only
generate join state locks, not generation counter locks.

* Code review feedback

Switches to require.EventuallyWithT()

* Remove fake clock

* Convert TestJoinBoundKeypair_JoinStateFailure_Instance to synctest

* Remove synctest in favor of inspecting the LockWatcher directly

* Persist JoinToken cert field in GenerateHostCerts

* Remove BuffconnListener
2026-04-20 22:57:58 +00:00
..