Skip to content

[v17] feat: Hardware Key Agent validates known keys#54907

Merged
Joerger merged 1 commit intobranch/v17from
joerger/v17/skip-validate-piv-cert
May 19, 2025
Merged

[v17] feat: Hardware Key Agent validates known keys#54907
Joerger merged 1 commit intobranch/v17from
joerger/v17/skip-validate-piv-cert

Conversation

@Joerger
Copy link
Copy Markdown
Contributor

@Joerger Joerger commented May 16, 2025

backport #54691 to branch/v17

Changelog: Hardware Key Agent validates known keys by checking active or expired login session.

* * Have hardware key agent validate known keys instead of always validating by the PIV slot cert.

* Refactor cert check logic with a custom error.

* Add test.

* Update rfd.

* Fix lint.

* Address comments.

* Require knownKeyFn to be provided.

* Require fallbackService to be provided to agent service.

* Address comments.
@github-actions github-actions Bot added backport size/md tsh tsh - Teleport's command line tool for logging into nodes running Teleport. labels May 16, 2025
@github-actions github-actions Bot requested review from greedy52 and rosstimothy May 16, 2025 22:53
@public-teleport-github-review-bot public-teleport-github-review-bot Bot removed the request for review from greedy52 May 19, 2025 13:16
@Joerger Joerger added this pull request to the merge queue May 19, 2025
Merged via the queue into branch/v17 with commit bdc2e74 May 19, 2025
41 checks passed
@Joerger Joerger deleted the joerger/v17/skip-validate-piv-cert branch May 19, 2025 18:39
@doggydogworld doggydogworld mentioned this pull request Jun 3, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport size/md tsh tsh - Teleport's command line tool for logging into nodes running Teleport.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants