Infrastructure Security Without Slowing Down Developers
gravitational.com
gravitational.com
The last section talks about choosing proxies over jumphosts, without mentioning what would be necessary to setup such a proxy. I would be really interested in a more indepth explanation of how such a proxy would work.
The author compares the proxy to a "dumb switch". How do you authenticate users without terminating encryption? And, if you don't authenticate users on the bastion, why bother with a bastion at all?
Now, "armed" with a certificate, the client can try again, in which case the proxy simply forwards the request to the destination host, which verifies the certificate. It is the same as having a non-terminating HTTP/TLS proxy/load balancer, just for SSH.
Quickstart: https://gravitational.com/teleport/docs/quickstart/
To quickly answer your question: if you rename teleport client "tsh" to "ssh", trying to use it without a certificate will trigger SSO workflow. The alternative is to issue "tsh login" CLI command in the morning.
Does anyone have experience using this? Besides giving auditing information, does this have any other benefits?
Basically, certificates rule the world everywhere, but due to rough UX, they haven't seen broad adoption for SSH. That's until now, hopefully :)
Are there any products/tools that make this easier? I've noticed that this isn't common even within companies with robust security infrastructure.
You just read an article by Gravitational, authors of Teleport. Check them out.
The opensource product is pretty full featured, the commercial version has a few features companies usually need (I believe SSO is one of them). Now instead of having people submit a ticket, send the keys, yada yada, you can just point someone to the portal and they can just use teleport credentials (or if you have the feature, the corp credentials). And the session is recorded. You can also use the command line – and it still gets recorded.
Disclaimer: We use Teleport in our company. I pitched after finding out about them here in HN. We still have bastion hosts, which now automation automatically deploys teleport and they show up in a single place.
This works nicely for my own personal setup with a few servers. It may be possible to scale this to a larger environment with multiple users too.
Then main benefit is that whenever a server is rebuilt (which can be quite regularly when using infra-as-code/infra automation), I don't have to go and manually update every single client that needs to be able to connect.
https://www.jamieweb.net/blog/managing-your-ssh-known_hosts-...
Another one to look at is https://github.com/Netflix/bless
Also, if you want to stick with what you have (most likely OpenSSH), we wrote an OpenSSH guide: https://gravitational.com/blog/how-to-ssh-properly/
There are a few floating around, I think this is one of the good ones: https://www.youtube.com/watch?v=JwLGsWYVjqU
It relies on Amazon’s Session Manager plugin, importing the user’s public key with aws ec2 import-key-pair, and firing up a new instance on the relevant subnet with the appropriate role, security group, etc.
I rather doubt the company would allow even something this simple to be distributed, unfortunately, at least without lawyers getting involved, hardly worth it for a 100 line bash script.