winget install --id Gravitational.TeleportConnect
About Teleport Connect
Teleport Connect provides easy and secure access to SSH servers, databases, applications, Windows desktops, and Kubernetes clusters.
What's new in 18.9.2
- Fixed HTTP application access connections returning repeated 403 errors after certificate renewal. When the certificate behind a long-lived connection expires, the proxy now sends Connection: close so the client reestablishes the connection with a renewed certificate instead of reusing a dead one. #68099 - Add "tsh apps logins" command to query available logins for the given cloud application (currently only AWS is supported). #68052 - Fixed cloud-hosted Slack plugin exposing credentials in request URLs. #68017 - Added the Sub CA tctl auth delete-override command, a user-friendly alternative over tctl edit ca_overrides or tctl rm ca_overrides. #68014 - Fixed potential deadlock when reading access list owners from the cache as the cache becomes unhealthy. #68013 - Added the Sub CA tctl auth create-override command, a user-friendly alternative over tctl create ca_override.yaml. #67983 - Fix MFA prompts to show correct --mfa-mode values for webauthn authenticators. #67971 - Prevent misrouting when multiple apps share the same public address. #67947 - Fix an issue where the WebUI would prompt for MFA multiple times for admin actions (or outright fail for select commands) when sso is the only allowed second factor on the cluster. #67867 - Fixed desktop connection failures to Windows 11 / Windows Server 2025 instances. #67483 Enterprise: - Add support for rate limiting in the Teleport SCIM Server. - Update golang.org/x/crypto to v0.53.0. - Updated Teleport Entra ID integration to support delta sync. - Only process Okta assignments for groups and apps currently being synced. - P...
Version history
| Version | Updated | Notes |
|---|---|---|
| 18.9.2 | Unknown | - Fixed HTTP application access connections returning repeated 403 errors after certificate renewal. When the certificate behind a long-lived connection expires, the proxy now sends Connection: close so the client reesta... |
| 18.9.1 | Unknown | - Fixed a limitation in Kubernetes Access causing the agent to throttle at 5 exec/second. |
| 18.9.0 | Unknown | Device Bound Session Credentials for App Access Application access session cookies are now compatible with Google's Device Bound Session Credentials, adding a layer of protection against session hijacking and cookie thef... |
| 18.8.3 | Unknown | - Fixed minor formatting bug on tsh request show output. #67447 - The embedded session helper functionality introduced in v18.8.0 to improve memory usage and latency of SSH sessions is now disabled by default due to inco... |
| 18.8.2 | Unknown | - Fixed tsh aws, tsh gcp, tsh azure, and tsh proxy app failing with certificate errors. #66962 - Fixed a regression introduced in v18.7.6 affecting connectivity to resources via approved just-in-time resource access requ... |
| 18.8.1 | Unknown | - Improved the performance of certain predicate expressions used to select SSH servers. #66769 - Fixes an issue preventing joins using the azure join method in regions where the trust chain has been updated with an addit... |
| 18.8.0 | Unknown | Performance improvements in the SSH service Thanks to internal improvements (#66220), the Teleport SSH service memory usage and latency when opening shells/running commands is significantly lower than previous versions.... |
| 18.7.6 | Unknown | No notes |
| 18.7.5 | Unknown | - Prevented a possible panic during TTY session processing/playback/summarization from crashing Teleport. - Fixed an upload failure for encrypted recordings near the 4MB limit caused by metadata exceeding the maximum mes... |
| 18.7.4 | Unknown | Teleport 18.7.4 |
| 18.7.3 | Unknown | Teleport 18.7.3 |
| 18.7.2 | Unknown | - Added TeleportAccessMonitoringRuleV1 support to the Teleport Kubernetes operator. #64368 - Added update scoped token support to tctl and update upsert scoped token rpc to not require status. #64345 - Improved performan... |
| 18.7.1 | Unknown | - Fixed web app access in leaf clusters when VNet is enabled. #63993 - Fixed an issue where desktop session recordings would show a white screen instead of the recording player, and fixed an issue where if a session's me... |
| 18.7.0 | Unknown | Session timeline view for Identity Security Session player for Identity Security users received an enhanced timeline view with per-command session breakdown. Organization-level auto-discovery for AWS EC2 instances AWS au... |
| 18.6.8 | Unknown | - Added --exec-cmd and --exec-arg flags to tsh proxy kube to allow launching custom commands like k9s directly without requiring environment variable workarounds. #63066 Enterprise: - Fixes a panic that occurred when Ext... |
| 18.6.7 | Unknown | - Revised help messages for event handler CLI commands. #63620 - Fixed tsh ssh user@foo=bar uptime from running serially if users did not have role:read permissions. #63612 - The minimum version of macOS required to run... |
| 18.6.6 | Unknown | - Fixed tsh/Linux sending a too-large username for device trust. #63387 - Fixed an issue where MCP JSON-RPC messages with mixed-case field names could be parsed inconsistently and re-serialized to lower cases. Teleport n... |
| 18.6.5 | Unknown | - Fixed a CredentialContainer error when attempting to log in to the Web UI with a hardware key using Firefox >=147.0.2. #63245 - Added support for deleting cluster alerts via tctl alerts rm <alertID> command. #63211 - U... |
| 18.6.4 | Unknown | - Fixed GCS session recording backend not respecting rate limits. #62986 - Fixed a bug where members of a former owner Access List retain the owner permissions grants of the former owned Access List. It also fixes the is... |
| 18.6.3 | Unknown | Teleport 18.6.3 |