Description
Without an expiration date on an Azure Key Vault secret, the intended rotation time for a stored credential or API key can be missed.
Potential impact
If an old credential remains valid, a leaked value may be exploitable for longer.
Remediation
Set attributes.exp to an expiration time suited to the secret’s lifecycle and rotate the credential beforehand. Secret values can still be retrieved after expiration, so revoke the credential in its originating system separately.
Examples
These excerpts refer to an existing keyVault1. Supply expirationTimestamp as the intended expiry in Unix seconds, according to your operational policy.
Before
bicep
resource keyVault1_secretid1 'Microsoft.KeyVault/vaults/secrets@2019-09-01' = {
parent: keyVault1
name: 'secretid1'
properties: {
value: 'string'
contentType: 'string'
}
}
After
bicep
param expirationTimestamp int
resource keyVault1_keyVaultSecret1 'Microsoft.KeyVault/vaults/secrets@2016-10-01' = {
parent: keyVault1
name: 'keyVaultSecret1'
properties: {
value: 'secretValue'
attributes: {
enabled: true
nbf: 1585206000
exp: expirationTimestamp
}
}
}