teleport

The easiest, and most secure way to access and protect all of your infrastructure.

AGPL-3.0 License

Stars
17.1K
Committers
305
teleport - Teleport 4.0.0-rc.3

Published by russjones over 5 years ago

Warning

Pre-releases are not production ready, use at your own risk!

Download

Download the current and previous releases of Teleport at https://gravitational.com/teleport/download

teleport - Teleport 3.2.6

Published by russjones over 5 years ago

This release of Teleport contains a security fix.

Description

As part of a routine security audit of Teleport, a security vulnerability was discovered that affects recent Teleport releases (3.2, 3.1, and 3.0).

Details

Due to a flaw in session handling logic, a user with valid credentials and session ID can prevent a session from being recorded in the Audit Log.

This vulnerability can be only exploited by clients that have valid user credentials, have access to a valid session ID, and within a small time window. There is no known way to exploit this vulnerability outside the cluster by non-authenticated users.

Actions

To mitigate the issue, nodes, proxies, and auth servers should be upgraded to the patched release. Upgrades should follow the normal Teleport upgrade procedure: https://gravitational.com/teleport/docs/admin-guide/#upgrading-teleport.

Download

Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.

teleport - 3.1.9

Published by russjones over 5 years ago

This release of Teleport contains a security fix.

Description

As part of a routine security audit of Teleport, a security vulnerability was discovered that affects recent Teleport releases (3.2, 3.1, and 3.0).

Details

Due to a flaw in session handling logic, a user with valid credentials and session ID can prevent a session from being recorded in the Audit Log.

This vulnerability can be only exploited by clients that have valid user credentials, have access to a valid session ID, and within a small time window. There is no known way to exploit this vulnerability outside the cluster by non-authenticated users.

Actions

To mitigate the issue, nodes, proxies, and auth servers should be upgraded to the patched release. Upgrades should follow the normal Teleport upgrade procedure: https://gravitational.com/teleport/docs/admin-guide/#upgrading-teleport.

Download

Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.

teleport - Teleport 3.0.6

Published by russjones over 5 years ago

This release of Teleport contains a security fix.

Description

As part of a routine security audit of Teleport, a security vulnerability was discovered that affects recent Teleport releases (3.2, 3.1, and 3.0).

Details

Due to a flaw in session handling logic, a user with valid credentials and session ID can prevent a session from being recorded in the Audit Log.

This vulnerability can be only exploited by clients that have valid user credentials, have access to a valid session ID, and within a small time window. There is no known way to exploit this vulnerability outside the cluster by non-authenticated users.

Actions

To mitigate the issue, nodes, proxies, and auth servers should be upgraded to the patched release. Upgrades should follow the normal Teleport upgrade procedure: https://gravitational.com/teleport/docs/admin-guide/#upgrading-teleport.

Download

Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.

teleport - Teleport 4.0.0-rc.2

Published by russjones over 5 years ago

Warning

Pre-releases are not production ready, use at your own risk!

Download

Download the current and previous releases of Teleport at https://gravitational.com/teleport/download

teleport - Teleport 4.0.0-beta.1

Published by russjones over 5 years ago

Warning

Pre-releases are not production ready, use at your own risk!

Download

Download the current and previous releases of Teleport at https://gravitational.com/teleport/download

teleport - 3.2.4

Published by russjones over 5 years ago

This release of Teleport contains multiple bug fixes.

Changes

  • Read cluster name from TELEPORT_SITE environment variable in tsh. #2675
  • Multiple improvements around logging in and saving tsh profiles. #2657

Since 3.2.0

  • Added --bind-addr to force tsh to bind to a specific port during SSO login. #2620
  • Fixed issue with --bind-addr implementation. #2650

Download

Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.

teleport - 3.2.2

Published by russjones over 5 years ago

This release of Teleport contains a bug fix.

Changes

  • Fixed issue with --bind-addr implementation. #2650

Since 3.2.0

  • Added --bind-addr to force tsh to bind to a specific port during SSO login. #2620

Download

Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.

teleport - 3.2.1

Published by russjones over 5 years ago

This release of Teleport contains a feature.

Changes

  • Added --bind-addr to force tsh to bind to a specific port during SSO login. #2620

Download

Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.

teleport - Teleport 3.2.0

Published by russjones over 5 years ago

This is a major Teleport release which introduces support for Amazon's managed Kubernetes offering (EKS) and several bug fixes.

Amazon EKS

Teleport now supports Amazon EKS by switching to the the impersonation API instead of the CSR API for certificate issuance.

Bugfixes

  • Fixed disconnect and session termination logic to support Kubernetes proxy. #2618
  • Added support for DynamoDB pagination for cases when capacity throttling is used. #2576

Upgrading to 3.2

Teleport 3.2 is meant to be a drop-in replacement for the 3.1. However, if your Teleport cluster already has Kubernetes integration turned on, you will need to update /etc/teleport.yaml configuration and move kubeconfig_file from auth_service to proxy_service/kubernetes.

Download

Download the current and previous releases of Teleport at https://gravitational.com/teleport/download

teleport - Teleport 3.2.0-rc.1

Published by russjones over 5 years ago

Warning

Pre-releases are not production ready, use at your own risk!

Download

Download the current and previous releases of Teleport at https://gravitational.com/teleport/download

teleport - Teleport 3.1.8

Published by russjones over 5 years ago

This release of Teleport contains a bug fix.

Changes

  • Fixed issue where SSO users TTL was set incorrectly. #2564

Download

Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.

teleport - Teleport 3.1.7

Published by russjones over 5 years ago

This release of Teleport contains a bug fix.

Changes

  • Fixed issue where tctl users ls output contained duplicates. #2569 #2107

Download

Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.

teleport - Teleport 3.1.6

Published by russjones over 5 years ago

This release of Teleport contains bug fixes, security fixes, and user experience improvements.

Changes

  • Use xdg-open instead of sensible-browser to open links on Linux. #2454
  • Increased SSO callback timeout to 180 seconds. #2483
  • Improved Teleport error messages when it fails to start. #2525
  • Sort tsh ls output by node name. #2511
  • Support different regions for S3 (sessions) and DynamoDB (audit log). #2007
  • Fixed syslog output even when Teleport is in debug mode. #2550
  • Fixed audit log naming conventions. #2388
  • Fixed issue where ~/.tsh/profile was deleted upon logout. #2546
  • Fixed output of tctl get to be compatible with tctl create. #2479
  • Fixed issue where multiple file upload with scp did not work correctly. #2094
  • Correctly set permissions TTY. #2540
  • Mitigated scp issues when connected to malicious server #2539

Download

Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.

teleport - Teleport 3.1.5

Published by russjones over 5 years ago

Teleport 3.1.5 contains a bug fix and security fix.

Bug fixes

  • Fixed issue where certificate authorities were not fetched during every login. #2526
  • Upgraded Go to 1.11.5 to mitigate CVE-2019-6486: CPU denial of service in P-521 and P-384 elliptic curve implementation.

Download

Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.

teleport - Teleport 3.0.5

Published by russjones over 5 years ago

Teleport 3.0.5 contains a security fix.

Bug fixes

  • Upgraded Go to 1.11.5 to mitigate CVE-2019-6486: CPU denial of service in P-521 and P-384 elliptic curve implementation.

Download

Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.

teleport - Teleport 2.7.9

Published by russjones over 5 years ago

Teleport 2.7.9 contains a security fix.

Bug fixes

  • Upgraded Go to 1.11.5 to mitigate CVE-2019-6486: CPU denial of service in P-521 and P-384 elliptic curve implementation.

Download

Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.

teleport - Teleport 3.1.4

Published by russjones almost 6 years ago

3.1.4

Teleport 3.1.4 contains one new feature and two bug fixes.

New Feature

  • Added support for GSuite as a SSO provider. #2455

Bug fixes

  • Fixed issue where Kubernetes groups were not being passed to remote clusters. #2484
  • Fixed issue where the client was pulling incorrect CA for trusted clusters. #2487

Download

Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.

teleport - Teleport 3.1.3

Published by alex-kovoy almost 6 years ago

Teleport 3.1.3 contains three security fixes

Bug Fixes

  • Updated xterm.js to mitigate a RCE in xterm.js.
  • Mitigate potential timing attacks during bearer token authentication. #2482
  • Fixed x509: certificate signed by unknown authority error when connecting to DynamoDB within Gravitational publish Docker image. #2473

Download

Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.

teleport - Teleport 3.0.4

Published by russjones almost 6 years ago

Teleport 3.0.4 contains two security fixes

Bug Fixes

  • Updated xterm.js to mitigate a RCE in xterm.js.
  • Mitigate potential timing attacks during bearer token authentication. #2482

Download

Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.