Skip to main content
Back to the connector catalogue

Connector

Teleport

API credential, entered client by client.

Self-hosted open-source access proxy (SSH, Kubernetes, database and internal web-app bastion) with session recording. Vigicap reads the cluster's authentication policy, the number of reachable resources, the number of accounts holding an administrator or auditor role, and whether the audit log holds recent events, to evaluate the ReCyF objectives « Sécurisation des accès distants » and « Maîtrise de l'administration des systèmes d'information ». Remote access that does not go through the bastion is not visible from this source.

01

What to create in the tool

The access is created in Teleport, not in Vigicap. Vigicap never asks for an administrator's password: it expects an API credential that you create, that you can see, and that you can revoke without us.

Where to generate it

Créez un compte local dédié (tctl users add) avec un rôle en lecture seule, puis enrôlez-lui son propre dispositif TOTP et communiquez le secret en base32 affiché à l'enrôlement. Les trois champs sont nécessaires : depuis la version 17, Teleport refuse de démarrer sans second facteur, un couple identifiant / mot de passe seul ne peut donc pas se connecter. N'utilisez jamais le compte d'un administrateur humain — ce compte doit être créé pour Vigicap et pour rien d'autre. Important : l'instance doit présenter un certificat TLS valide et reconnu ; le certificat auto-signé généré par défaut par le proxy Teleport sera refusé par Vigicap (aucune option pour désactiver la vérification TLS, par sécurité).

Minimum role

Créez un rôle dédié accordant uniquement `read`/`list` sur user, role, node, event, session et cluster_auth_preference, plus `node_labels: {'*': '*'}` avec `logins: []`. Les labels sont indispensables : sans eux la liste des ressources revient VIDE au lieu de refuser, et `logins` vide garantit que le compte voit le parc sans pouvoir y ouvrir de session. N'utilisez pas les rôles intégrés `editor` ou `access`.

Taken from the vendor's own role model, and checked before publication.

02

What to enter in Vigicap

The exact fields of the connection form, in the order they appear. Values marked “secret” never travel back to the browser: they are encrypted at rest and deleted on disconnection.

The form starts with the instance address, entered separately from the fields below. The public catalogue does not yet publish whether this connector needs one, or what it looks like — so this list is exact about everything else, and silent about that first field.

  • Nom d'utilisateursecret

    Compte local Teleport dédié, créé avec tctl users add.

    vigicap

  • Mot de passesecret

    Mot de passe associé à ce compte.

  • Secret TOTPsecret

    Secret en base32 du dispositif TOTP enrôlé sur ce compte (affiché à côté du QR code lors de l'enrôlement). Teleport impose un second facteur : sans ce secret, la connexion est impossible.

    JBSWY3DPEHPK3PXP

03

Per-client routing

The connection is made client by client: one credential per client, entered on that client's record. Nothing is shared between two clients, and disconnecting one leaves the other untouched.

04

What it does, and what it does not do

ReCyF objectives it pre-fills

A reading feeds 2 objectives of the ANSSI ReCyF framework. It PROPOSES them: a level only counts once a consultant has confirmed it.

  • #8 Sécurisation des accès distants aux systèmes d'informationSecuring remote access to the information systems
  • #11 Maîtrise de l'administration des systèmes d'informationControl of the administration of the information systems

Read-only

The reads are read-only: Vigicap writes nothing into the tool while reading it.

What is read, what is kept, for how long and with which rights: the same register, connector by connector, in the data inventory.

Verification

This connector has been run end to end against a real instance of the tool, not merely tested against a mock.

The trademarks and logos mentioned belong to their respective owners and identify the tools Vigicap is compatible with — see the legal notice.