Limits of Teleport's certificate_revocation_check on Active SSH Sessions
0 reputation · 12 Dec 2025, 07:47 UTC
Goal: Determine whether an expired user certificate triggers immediate termination of an existing Teleport‑managed SSH (or Kubernetes) session when the Auth Server’s certificate_revocation_check flag is enabled.
Uncertainty: The documentation states that certificate expiry causes authentication handshake failures for new connections but does not specify if active sessions are torn down. Behavior may vary between Teleport Open Source and Enterprise editions, and settings such as idle_timeout or max_session_ttl can influence when reauthentication occurs, making it unclear if the flag alone can enforce least‑privilege revocation in‑flight.
Questions: Does enabling certificate_revocation_check cause Teleport to close active sessions upon certificate expiry? If not, what configuration or mechanism can be used to enforce immediate session termination? How do idle_timeout and max_session_ttl interact with this behavior?