Description
Writing Password directly in CloudFormation’s AWS::DirectoryService::SimpleAD, or in a parameter Default, leaves the directory administrator password in code and history.
Potential impact
Someone with connectivity to the directory and the leaked password could use the Administrator account to change directory resources, including users and groups.
Remediation
Supply the password through a secure deployment process without a default. Set NoEcho: true on the parameter and keep the password out of outputs and metadata. Reset an exposed existing password with ResetUserPassword. Changing the CloudFormation Password property replaces the directory, so do not use it for rotation.
Examples
Supply the VPC ID and two subnets in different Availability Zones within that VPC. The original password is illustrative. In the revised template, securely pass a value meeting the directory’s password policy through ParentMasterPassword.
Before
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
VpcId:
Type: AWS::EC2::VPC::Id
DirectorySubnets:
Type: List<AWS::EC2::Subnet::Id>
Resources:
NewAmpApp1:
Type: AWS::DirectoryService::SimpleAD
Properties:
Name: corp.example.com
Password: "asDjskjs73!!"
ShortName: CORP
Size: Small
VpcSettings:
VpcId: !Ref VpcId
SubnetIds: !Ref DirectorySubnets
After
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
ParentMasterPassword:
Type: String
NoEcho: true
MinLength: 8
MaxLength: 64
VpcId:
Type: AWS::EC2::VPC::Id
DirectorySubnets:
Type: List<AWS::EC2::Subnet::Id>
Resources:
NewAmpApp1:
Type: AWS::DirectoryService::SimpleAD
Properties:
Name: corp.example.com
Password: !Ref ParentMasterPassword
ShortName: CORP
Size: Small
VpcSettings:
VpcId: !Ref VpcId
SubnetIds: !Ref DirectorySubnets