Azure Key Vault secret has no expiration date

Set a rotation deadline and replace credentials before it.

Description

Without an expiration date on an Azure Key Vault secret, the intended rotation time for a stored credential or API key can be missed.

Potential impact

If an old credential remains valid, a leaked value may be exploitable for longer.

Remediation

Set attributes.exp to an expiration time suited to the secret’s lifecycle and rotate the credential beforehand. Secret values can still be retrieved after expiration, so revoke the credential in its originating system separately.

Examples

These excerpts refer to an existing keyVault1. Supply expirationTimestamp as the intended expiry in Unix seconds, according to your operational policy.

Before

bicep
resource keyVault1_secretid1 'Microsoft.KeyVault/vaults/secrets@2019-09-01' = {
  parent: keyVault1
  name: 'secretid1'
  properties: {
    value: 'string'
    contentType: 'string'
  }
}

After

bicep
param expirationTimestamp int

resource keyVault1_keyVaultSecret1 'Microsoft.KeyVault/vaults/secrets@2016-10-01' = {
  parent: keyVault1
  name: 'keyVaultSecret1'
  properties: {
    value: 'secretValue'
    attributes: {
      enabled: true
      nbf: 1585206000
      exp: expirationTimestamp
    }
  }
}

References