Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[v15] Cache PIV connections to share across the program execution #47953

Merged
merged 4 commits into from
Nov 21, 2024

Conversation

gzdunek
Copy link
Contributor

@gzdunek gzdunek commented Oct 25, 2024

Backport #47091 to branch/v15

Manual backport because of some minor conflicts.

changelog: Resolved an issue that caused false positive errors incorrectly indicating that the YubiKey was in use by another application, while only tsh was accessing it

* Cache yubikey objects.

* Cache PIV connections to share across the program execution.

* Do not release the connection until `sign` returns

* Do not ignore errors

* Perform a "warm up" call to YubiKey

* Fix tests

* Use a specific interface to check if the key can be "warmed up"

* Allow abandoning `signer.Sign` call when context is canceled

* Make sure that the cached key is valid for the given private key policy

The reason for adding this check was failing `invalid key policies` test.

* Make `hardwareKeyWarmer` private

* Force callers to release connection

* Improve comments

* Fix lint

* Improve `connect` comment

* Fix race condition

* Simplify `release` logic

* Trigger license/cla

---------

Co-authored-by: joerger <bjoerger@goteleport.com>

(cherry picked from commit bd6fdbf)
Copy link

This pull request is automatically being deployed by Amplify Hosting (learn more).

Access this pull request here: https://pr-47953.d1v2yqnl3ruxch.amplifyapp.com

@public-teleport-github-review-bot public-teleport-github-review-bot bot removed the request for review from nklaassen October 25, 2024 17:26
@Joerger Joerger mentioned this pull request Nov 6, 2024
gzdunek and others added 3 commits November 14, 2024 15:36
Otherwise, signing may fail with "input must be a hashed message" error.

(cherry picked from commit 47494db)
…n from leaking after program execution. (#48414)

(cherry picked from commit b7c0e79)
@gzdunek gzdunek added this pull request to the merge queue Nov 21, 2024
Merged via the queue into branch/v15 with commit 9f54a56 Nov 21, 2024
35 checks passed
@gzdunek gzdunek deleted the gzdunek/backport-47091/v15 branch November 21, 2024 17:43
@camscale camscale mentioned this pull request Dec 6, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants