Description
An unnecessary active long-term access key can be used for AWS requests with its user's permissions if the required credentials are exposed. Check the key's actual owner, status and usage, and move to roles and temporary credentials where possible.
An IAM user and the AWS account root user are different identities. An IAM user whose name includes root does not become the account's root user. Review actual root-user credentials separately and follow AWS's recommendation not to create long-term root access keys.
Potential impact
- An active key and the required secret information can be misused within the user's permissions. Actual impact depends on attached policies and other controls.
- Disabling a key without identifying its consumers can interrupt automation or services.
Remediation
- Identify the actual IAM user and key ID, and review current status and usage. Check the generation time of credential reports and obtain current status separately when needed.
- Prepare replacement authentication for required automation, then disable the explicitly identified key. Verify normal operation before deleting an unnecessary key. Distinguish the credentials used to administer keys from the key being managed.
- Review root access keys and root sign-in protection separately. Use appropriately restricted roles and temporary credentials for everyday work.
Examples
Set iam_user_name and access_key_id to the actual IAM user and the target key owned by that user. amazon.aws.iam_access_key manages IAM user keys; these examples do not manage root-user keys. Configure suitable, separate AWS authentication in the execution environment.
Before
- name: Enable a selected IAM user access key
amazon.aws.iam_access_key:
user_name: "{{ iam_user_name }}"
id: "{{ access_key_id }}"
state: present
active: true
The specified IAM user key is activated. Do this only when the key has a required purpose.
After
- name: Disable a selected IAM user access key
amazon.aws.iam_access_key:
user_name: "{{ iam_user_name }}"
id: "{{ access_key_id }}"
state: present
active: false
The same key is disabled without being deleted. Verify dependent workloads and the actual key status, then delete the key if it is no longer needed.