Description
IAM user access keys are long-term credentials. Keeping unnecessary keys active increases the opportunity for disclosure or misuse. An active key is not evidence of a leak, and an access key ID alone cannot authenticate requests: the corresponding secret access key is also required.
Prefer federation and temporary credentials for people and roles for workloads. Where a long-term key is necessary, manage its owner, purpose, usage and permissions. Root user access keys are not an alternative.
Potential impact
- Disclosure of an active key and its secret can allow misuse of the user's permitted actions.
- Unused keys complicate credential management, while disabling a key without checking its dependencies can interrupt services.
Remediation
- Check the key's actual owner and usage, and move required automation to roles or temporary credentials.
- Test replacement authentication before deactivating unnecessary keys, then delete them after confirming normal operation. Replace and revoke suspected exposed credentials and investigate their use.
- Apply least privilege to keys that must remain and keep their secrets out of repositories, logs and source code.
Examples
These examples use the current IAM user access key module to change the same key's state. Supply the actual IAM user and a key ID belonging to that user. Configure separate AWS authentication for running the module.
Before
- name: Enable a selected IAM user access key
amazon.aws.iam_access_key:
user_name: "{{ iam_user_name }}"
id: "{{ access_key_id }}"
state: present
active: true
This enables the selected key. Confirm that it serves a legitimate operational need.
After
- name: Disable a selected IAM user access key
amazon.aws.iam_access_key:
user_name: "{{ iam_user_name }}"
id: "{{ access_key_id }}"
state: present
active: false
This deactivates the same key without deleting it. Verify dependent workloads and the key's actual state.