Files
teleport/docs/pages/setup/reference/authentication.mdx
T
Paul Gottschling 10e8346b10 Fix meta description clash (#10621)
* Fix meta description clash

Two docs pages had the same meta description, which hurts SEO.
This changes the meta description of one of the page and uses
this opportunity to do some light copy editing.

Fixes #8713

* Respond to PR feedback
2022-03-02 22:25:12 +00:00

113 lines
3.7 KiB
Plaintext

---
title: Authentication options
description: A reference for Teleport's authentication connectors
---
Teleport authenticates users with an identity provider via **authentication
connectors**. There are three types of authentication connectors.
## Local (no authentication connector)
Local authentication is used to authenticate against a local Teleport user
database. This database is managed by the [`tctl users`](./cli.mdx#tctl-users-add)
command. Teleport also supports second-factor authentication (2FA) for the local
connector. There are several possible values (types) of 2FA:
- `otp` is the default. It implements the [TOTP](https://en.wikipedia.org/wiki/Time-based_One-time_Password_Algorithm)
standard. You can use [Google Authenticator](https://en.wikipedia.org/wiki/Google_Authenticator), [Authy],(https://www.authy.com/) or any other TOTP client.
- `webauthn` implements the [Web Authentication standard](https://webauthn.guide) for utilizing
second factor authenticators and hardware devices.
You can use [YubiKeys](https://www.yubico.com/), [SoloKeys](https://solokeys.com/) or any other authenticator that
implements FIDO2 or FIDO U2F standards.
See our [Second Factor - WebAuthn](../../access-controls/guides/webauthn.mdx) guide for detailed
instructions on setting up WebAuthn for Teleport.
- `on` enables both TOTP and WebAuthn, and all local users are required to have at least one 2FA device registered.
- `optional` enables both TOTP and WebAuthn but makes it optional for users. Local users that register a 2FA device will
be prompted for it during login. This option is useful when you need to gradually enable 2FA usage before switching
the value to `on`.
- `off` turns off second-factor authentication.
You can modify these settings in the static config `teleport.yaml` or using dynamic configuration resources:
<Tabs>
<TabItem label="Static Config (self-hosted)">
```yaml
auth_service:
authentication:
type: local
second_factor: off
```
</TabItem>
<TabItem label="Dynamic resources (all editions)">
Create a file `cap.yaml`:
```yaml
kind: cluster_auth_preference
metadata:
name: cluster-auth-preference
spec:
type: local
second_factor: "on"
webauthn:
rp_id: 'example.teleport.sh'
version: v2
```
Create a resource:
```code
$ tctl create -f cap.yaml
```
</TabItem>
</Tabs>
<Admonition type="note">
SSO users can also register 2FA devices, but Teleport will not prompt them for 2FA during login. Login 2FA for SSO users should be handled by the SSO provider.
</Admonition>
## GitHub
This connector implements GitHub's OAuth 2.0 authentication flow. Please refer to GitHub's documentation on [Creating an OAuth App](https://developer.github.com/apps/building-oauth-apps/creating-an-oauth-app/)
to learn how to create and register an OAuth app.
Here is an example of this setting in the `teleport.yaml` :
```yaml
auth_service:
authentication:
type: github
```
See [Github OAuth 2.0](../admin/github-sso.mdx) for details on how to configure it.
## SAML
<Notice type="note">
You need the Enterprise edition of Teleport for this option.
</Notice>
This connector type implements SAML authentication. It can be configured against any external identity manager like Okta or Auth0. This feature is only available for Teleport Enterprise.
Here is an example of this setting in the `teleport.yaml` :
```yaml
auth_service:
authentication:
type: saml
```
### OIDC
<Notice type="note">
You need the Enterprise edition of Teleport for this option.
</Notice>
Teleport implements OpenID Connect (OIDC) authentication, which is similar to SAML in principle.
Here is an example of this setting in the `teleport.yaml` :
```yaml
auth_service:
authentication:
type: oidc
```