Session-centric access control for secure ephemeral shells
Technologies are shown for session centric access control of a remote connection. A request for a remote connection is received from a client. A container is created for the remote connection, and an identifier for each of one or more endpoints authorized for the remote connection are stored in the container. A secure shell is initiated for the remote connection. Access is provided to the first endpoint from the one or more endpoints via the secure shell based on a first identifier for the first endpoint being stored in the container.
1. A computer-implemented method comprising:
receiving, from a client, a request for a remote connection;
creating a container for the remote connection;
storing, in the container, an identifier for each of one or more endpoints authorized for the remote connection;
initiating a secure shell for the remote connection;
receiving, from a first endpoint, a query in response to the first endpoint receiving an access request from the client;
determining that a first identifier for the first endpoint is stored in the container; and
based on determining the first identifier for the first endpoint is stored in the container, sending a message to the first endpoint indicating that the client is authorized to access the first endpoint.
2. The computer-implemented method of claim 1 , wherein the method further comprises:
storing, in the container, a certificate and a public key for the remote connection.
3. The computer-implemented method of claim 2 , wherein the secure shell for the remote connection is initiated using the certificate, the public key, and single use credentials.
4. The computer-implemented method of claim 1 , wherein the one or more endpoints are authorized based on a profile or a role for the client.
5. The computer-implemented method of claim 1 , wherein the one or more endpoints are authorized based on a type of task requested for the remote connection.
6. The computer-implemented method of claim 1 , wherein the identifier for the first endpoint comprises a private key.
7. One or more computer storage media storing computer-useable instructions that, when used by a computing device, cause the computing device to perform operations, the operations comprising:
receiving, from a client, a request for a remote connection;
creating a container for the remote connection;
storing, in the container, an identifier for each of one or more endpoints authorized for the remote connection;
initiating a secure shell for the remote connection;
receiving, from a first endpoint, a query in response to the first endpoint receiving an access request from the client;
determining that a first identifier for the first endpoint is stored in the container; and
based on determining the first identifier for the first endpoint is stored in the container, sending a message to the first endpoint indicating that the client is authorized to access the first endpoint.
8. The one or more computer storage media of claim 7 , wherein the operations further comprise:
storing, in the container, a certificate and a public key for the remote connection.
9. The one or more computer storage media of claim 8 , wherein the secure shell for the remote connection is initiated using the certificate, the public key, and single use credentials.
10. The one or more computer storage media of claim 7 , wherein the one or more endpoints are authorized based on a profile or a role for the client.
11. The one or more computer storage media of claim 7 , wherein the one or more endpoints are authorized based on a type of task requested for the remote connection.
12. The one or more computer storage media of claim 7 , wherein the identifier for the first endpoint comprises a private key.
13. A computer system comprising:
a processor; and
a computer storage medium storing computer-useable instructions that, when used by the processor, causes the computer system to perform operations comprising:
receiving, from a client, a request for a remote connection;
creating a container for the remote connection;
storing, in the container, an identifier for each of one or more endpoints authorized for the remote connection;
initiating a secure shell for the remote connection;
receiving, from a first endpoint, a query in response to the first endpoint receiving an access request from the client;
determining that a first identifier for the first endpoint is stored in the container; and
based on determining the first identifier for the first endpoint is stored in the container, sending a message to the first endpoint indicating that the client is authorized to access the first endpoint.
14. The computer system of claim 13 , wherein the operations further comprise:
storing, in the container, a certificate and a public key for the remote connection.
15. The computer system of claim 14 , wherein the secure shell for the remote connection is initiated using the certificate, the public key, and single use credentials.
16. The computer system of claim 13 , wherein the one or more endpoints are authorized based on a profile or a role for the client.
17. The computer system of claim 13 , wherein the one or more endpoints are authorized based on a type of task requested for the remote connection.