v17.7.18

gravitational/teleportv17.7.18Feb 10, 2026by doggydogworld

AI Summary

Teleport 17.7.18 raises minimum macOS requirements to version 12 and includes various bug fixes for device trust and PAM authentication.

Key Highlights

  • Minimum macOS version raised to macOS 12 (Monterey)
  • Updated Go to 1.25.7
  • Fixed device trust issues with tsh/Linux
  • Fixed PAM auth modules failing with exec sessions
  • Fixed event handler issues with large events on DynamoDB and Athena backends

Breaking Changes

  • macOS 12 (Monterey) is now the minimum required version for Teleport and Teleport Connect (previously macOS 11)

New Features

  • Access Monitoring feature extended to Teleport Cloud customers using External Audit Storage
  • Recording and validation for OS login user values from tsh

Full Release Notes

## Description

Skipped 17.7.17 due to a build pipeline issue.

* Revised help messages for event handler CLI commands. [#63642](https://github.com/gravitational/teleport/pull/63642)
* Fixed `tsh ssh user@foo=bar uptime` from running serially if users did not have `role:read` permissions. [#63611](https://github.com/gravitational/teleport/pull/63611)
* The minimum version of macOS required to run Teleport or associated client tools is now macOS 12 (Monterey). [#63588](https://github.com/gravitational/teleport/pull/63588)
* The minimal macOS version required by Teleport Connect is now macOS 12. [#63570](https://github.com/gravitational/teleport/pull/63570)
* Fixed bug where event handler would get stuck on DynamoDB backend when handling large events. [#63562](https://github.com/gravitational/teleport/pull/63562)
* Updated Go to 1.25.7. [#63561](https://github.com/gravitational/teleport/pull/63561)
* Fixed bug where event handler would throw an error on Athena backend when handling large events. [#63551](https://github.com/gravitational/teleport/pull/63551)
* Fixed an issue where a role requiring a trusted device could incorrectly block access to all applications. [#63528](https://github.com/gravitational/teleport/pull/63528)
* Updated tsh/Linux to correctly capture the OS login user for device trust. [#63453](https://github.com/gravitational/teleport/pull/63453)
* Fixed a server error when rejecting a headless authentication request in the Web UI. [#63432](https://github.com/gravitational/teleport/pull/63432)
* Fixed tsh/Linux sending a too-large username for device trust. [#63388](https://github.com/gravitational/teleport/pull/63388)
* Fixed teleport join openssh on recent versions of Ubuntu. [#63042](https://github.com/gravitational/teleport/pull/63042)
* Fix an issue in the Teleport SSH Service where interactive PAM Auth modules always fail when trying to run exec sessions with tty allocated. e.g. `tsh ssh --tty <node> ls`. [#62065](https://github.com/gravitational/teleport/pull/62065)

Enterprise:
* Extend Access Monitoring feature to Teleport Cloud customers using External Audit Storage.
* Added recording and validation for the fixed OS login user values from tsh.

## Download

Download the current and previous releases of Teleport at https://goteleport.com/download.

## Plugins

Download the current release of Teleport plugins from the links below.
* Slack [Linux amd64](https://cdn.teleport.dev/teleport-access-slack-v17.7.18-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-slack-v17.7.18-linux-arm64-bin.tar.gz) 
* Mattermost [Linux amd64](https://cdn.teleport.dev/teleport-access-mattermost-v17.7.18-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-mattermost-v17.7.18-linux-arm64-bin.tar.gz)
* Discord [Linux amd64](https://cdn.teleport.dev/teleport-access-discord-v17.7.18-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-discord-v17.7.18-linux-arm64-bin.tar.gz)
* Terraform Provider [Linux amd64](https://cdn.teleport.dev/terraform-provider-teleport-v17.7.18-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/terraform-provider-teleport-v17.7.18-linux-arm64-bin.tar.gz) | [macOS amd64](https://cdn.teleport.dev/terraform-provider-teleport-v17.7.18-darwin-amd64-bin.tar.gz) | [macOS arm64](https://cdn.teleport.dev/terraform-provider-teleport-v17.7.18-darwin-arm64-bin.tar.gz) | [macOS universal](https://cdn.teleport.dev/terraform-provider-teleport-v17.7.18-darwin-universal-bin.tar.gz)
* Event Handler [Linux amd64](https://cdn.teleport.dev/teleport-event-handler-v17.7.18-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-event-handler-v17.7.18-linux-arm64-bin.tar.gz) | [macOS amd64](https://cdn.teleport.dev/teleport-event-handler-v17.7.18-darwin-amd64-bin.tar.gz)
* PagerDuty [Linux amd64](https://cdn.teleport.dev/teleport-access-pagerduty-v17.7.18-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-pagerduty-v17.7.18-linux-arm64-bin.tar.gz)
* Jira [Linux amd64](https://cdn.teleport.dev/teleport-access-jira-v17.7.18-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-jira-v17.7.18-linux-arm64-bin.tar.gz)
* Email [Linux amd64](https://cdn.teleport.dev/teleport-access-email-v17.7.18-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-email-v17.7.18-linux-arm64-bin.tar.gz)
* Microsoft Teams [Linux amd64](https://cdn.teleport.dev/teleport-access-msteams-v17.7.18-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-msteams-v17.7.18-linux-arm64-bin.tar.gz)