Expose OU and other LDAP attributes/characteristics to use in RBAC for Windows machines #11575
Labels
desktop-access
feature-request
Used for new features in Teleport, improvements to current should be #enhancements
rbac
Issues related to Role Based Access Control
windows
What
The current
host_labels
logic for Windows machines is good but doesn't allow you to build labels for RBAC based on LDAP OU or similar. It'd be good to expose LDAP OU or maybe even a full DN and allow labels to match against this to allow more sophisticated labelling.How
Have a fuller set of LDAP characteristics/attributes exposed and let Teleport do matching against these as well as the machine's hostname.
Why
Bigger estates often don't have coherent hostnames which expose enough information about the machine to let you build RBAC rules based on hostname only. By contrast, LDAP OU and DN is usually far more specific.
Workaround
It's possible to work around this currently by running multiple agents providing a
windows_desktop_service
which have a different configuredbase_dn
:This is cumbersome and adds a lot of overhead, however.
The text was updated successfully, but these errors were encountered: