mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
* Fix meta description clash Two docs pages had the same meta description, which hurts SEO. This changes the meta description of one of the page and uses this opportunity to do some light copy editing. Fixes #8713 * Respond to PR feedback
113 lines
3.7 KiB
Plaintext
113 lines
3.7 KiB
Plaintext
---
|
|
title: Authentication options
|
|
description: A reference for Teleport's authentication connectors
|
|
---
|
|
|
|
Teleport authenticates users with an identity provider via **authentication
|
|
connectors**. There are three types of authentication connectors.
|
|
|
|
## Local (no authentication connector)
|
|
|
|
Local authentication is used to authenticate against a local Teleport user
|
|
database. This database is managed by the [`tctl users`](./cli.mdx#tctl-users-add)
|
|
command. Teleport also supports second-factor authentication (2FA) for the local
|
|
connector. There are several possible values (types) of 2FA:
|
|
|
|
- `otp` is the default. It implements the [TOTP](https://en.wikipedia.org/wiki/Time-based_One-time_Password_Algorithm)
|
|
standard. You can use [Google Authenticator](https://en.wikipedia.org/wiki/Google_Authenticator), [Authy],(https://www.authy.com/) or any other TOTP client.
|
|
- `webauthn` implements the [Web Authentication standard](https://webauthn.guide) for utilizing
|
|
second factor authenticators and hardware devices.
|
|
You can use [YubiKeys](https://www.yubico.com/), [SoloKeys](https://solokeys.com/) or any other authenticator that
|
|
implements FIDO2 or FIDO U2F standards.
|
|
See our [Second Factor - WebAuthn](../../access-controls/guides/webauthn.mdx) guide for detailed
|
|
instructions on setting up WebAuthn for Teleport.
|
|
- `on` enables both TOTP and WebAuthn, and all local users are required to have at least one 2FA device registered.
|
|
- `optional` enables both TOTP and WebAuthn but makes it optional for users. Local users that register a 2FA device will
|
|
be prompted for it during login. This option is useful when you need to gradually enable 2FA usage before switching
|
|
the value to `on`.
|
|
- `off` turns off second-factor authentication.
|
|
|
|
You can modify these settings in the static config `teleport.yaml` or using dynamic configuration resources:
|
|
|
|
<Tabs>
|
|
<TabItem label="Static Config (self-hosted)">
|
|
```yaml
|
|
auth_service:
|
|
authentication:
|
|
type: local
|
|
second_factor: off
|
|
```
|
|
</TabItem>
|
|
<TabItem label="Dynamic resources (all editions)">
|
|
Create a file `cap.yaml`:
|
|
```yaml
|
|
kind: cluster_auth_preference
|
|
metadata:
|
|
name: cluster-auth-preference
|
|
spec:
|
|
type: local
|
|
second_factor: "on"
|
|
webauthn:
|
|
rp_id: 'example.teleport.sh'
|
|
version: v2
|
|
```
|
|
|
|
Create a resource:
|
|
|
|
```code
|
|
$ tctl create -f cap.yaml
|
|
```
|
|
</TabItem>
|
|
</Tabs>
|
|
|
|
<Admonition type="note">
|
|
SSO users can also register 2FA devices, but Teleport will not prompt them for 2FA during login. Login 2FA for SSO users should be handled by the SSO provider.
|
|
</Admonition>
|
|
|
|
## GitHub
|
|
|
|
This connector implements GitHub's OAuth 2.0 authentication flow. Please refer to GitHub's documentation on [Creating an OAuth App](https://developer.github.com/apps/building-oauth-apps/creating-an-oauth-app/)
|
|
to learn how to create and register an OAuth app.
|
|
|
|
Here is an example of this setting in the `teleport.yaml` :
|
|
|
|
```yaml
|
|
auth_service:
|
|
authentication:
|
|
type: github
|
|
```
|
|
|
|
See [Github OAuth 2.0](../admin/github-sso.mdx) for details on how to configure it.
|
|
|
|
## SAML
|
|
|
|
<Notice type="note">
|
|
You need the Enterprise edition of Teleport for this option.
|
|
</Notice>
|
|
|
|
This connector type implements SAML authentication. It can be configured against any external identity manager like Okta or Auth0. This feature is only available for Teleport Enterprise.
|
|
|
|
Here is an example of this setting in the `teleport.yaml` :
|
|
|
|
```yaml
|
|
auth_service:
|
|
authentication:
|
|
type: saml
|
|
```
|
|
|
|
### OIDC
|
|
|
|
<Notice type="note">
|
|
You need the Enterprise edition of Teleport for this option.
|
|
</Notice>
|
|
|
|
Teleport implements OpenID Connect (OIDC) authentication, which is similar to SAML in principle.
|
|
|
|
Here is an example of this setting in the `teleport.yaml` :
|
|
|
|
```yaml
|
|
auth_service:
|
|
authentication:
|
|
type: oidc
|
|
```
|