This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+13 more
Affected surfaces
Summary
AI summaryBroad release touches Other fixes and improvements, Description, https://github.com/gravitational/teleport/pull/67532, and https://github.com/gravitational/teleport/pull/67502.
Full changelog
Description
Device Bound Session Credentials for App Access
Application access session cookies are now compatible with Google's Device Bound
Session Credentials, adding a layer of protection against session hijacking and
cookie theft.
High-DPI support for Windows desktop sessions
Remote desktop sessions now support high-DPI mode, improving the clarity and
quality of the display rendering on supported displays.
Sub-CA
Teleport now supports operating as a sub-CA of an external root for the Windows
Desktop and Database Client CAs. Subsequent releases will extend support for
other CAs.
Other fixes and improvements
- Outdated agents joining via the legacy Auth HTTP endpoint now receive an explicit "client too old" error instead of a confusing 404. #67532
- Rename --from/--to to --from-utc/--to-utc on
recordings searchto match therecordings lsflag naming convention. #67502 - Improved performance and reduced resource usage of the auth service for clusters with large numbers of registered applications with per-session MFA enabled. #67471
- Prevented ssh users from being able to cancel other users' remote port forwards. #67442
- Improved application server resolution times for large number of applications. #62585
Download
Download the current and previous releases of Teleport at https://goteleport.com/download.
Plugins
Download the current release of Teleport plugins from the links below.
- Slack Linux amd64 | Linux arm64
- Mattermost Linux amd64 | Linux arm64
- Discord Linux amd64 | Linux arm64
- Terraform Provider Linux amd64 | Linux arm64 | macOS amd64 | macOS arm64 | macOS universal
- Event Handler Linux amd64 | Linux arm64 | macOS amd64
- PagerDuty Linux amd64 | Linux arm64
- Jira Linux amd64 | Linux arm64
- Email Linux amd64 | Linux arm64
- Microsoft Teams Linux amd64 | Linux arm64
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About teleport
The easiest, and most secure way to access and protect all of your infrastructure.
Related context
Related tools
Earlier breaking changes
- v18.10.0 Kubernetes ephemeral container addition now requires both exec and patch/update verbs.
- v18.8.3 Embedded session helper disabled by default; enable via `TELEPORT_UNSTABLE_DISABLE_EMBEDDED_REEXEC=no`.
- v18.8.0 Roles with unknown fields rejected at create/edit instead of silently dropped.
- v18.8.0 Teleport Connect automatic updates only; manual downgrades required.
Beta — feedback welcome: [email protected]