Description
A leaked long-lived access key can be misused until it is revoked. AWS Config ACCESS_KEYS_ROTATED evaluates the age of active IAM user keys; it does not rotate or deactivate them automatically.
Potential impact
Old or unused keys that remain valid leave unnecessary credentials in place and can complicate incident response.
Remediation
Prefer IAM roles and temporary credentials. If your organization applies a 90-day limit to long-lived keys, set maxAccessKeyAge to 90 or less and operate a process to rotate keys, update consumers, and deactivate and delete old keys.
Examples
The examples change the evaluation threshold from 100 days to 90 days. AWS Config setup is separate, and this rule does not evaluate root user keys.
Before
Resources:
ConfigRule:
Type: AWS::Config::ConfigRule
Properties:
ConfigRuleName: access-keys-rotated
InputParameters:
maxAccessKeyAge: 100
Source:
Owner: AWS
SourceIdentifier: ACCESS_KEYS_ROTATED
MaximumExecutionFrequency: TwentyFour_Hours
Key age is evaluated against a 100-day threshold.
After
Resources:
ConfigRule:
Type: AWS::Config::ConfigRule
Properties:
ConfigRuleName: access-keys-rotated
InputParameters:
maxAccessKeyAge: 90
Source:
Owner: AWS
SourceIdentifier: ACCESS_KEYS_ROTATED
MaximumExecutionFrequency: TwentyFour_Hours
The threshold is 90 days. This change alone does not expire or rotate keys.