RDS IAM database authentication is not enabled

Use IAM authentication on supported RDS instances to reduce reliance on long-term database passwords.

Description

Without IAM database authentication, applications may rely on separately managed database credentials. Supported RDS for MariaDB, MySQL and PostgreSQL instances can accept IAM authentication tokens. A token is valid for authenticating new connections for 15 minutes; it does not limit the lifetime of an established session.

Potential impact

Storing or sharing long-term passwords across systems can increase the risk of exposure and missed access revocation.

Remediation

Check engine, version and application support, then set EnableIAMDatabaseAuthentication: true. Configure a database user for IAM authentication, the required rds-db:connect permission and a TLS connection. Manage database privileges and audit logs separately. For Aurora, configure IAM authentication on the cluster rather than the instance.

Examples

These excerpts assume a read replica of an encrypted RDS MySQL source. Supply its identifier and Region, a supported instance class and a usable KMS key through the omitted MyKey definition.

Before

yaml
AWSTemplateFormatVersion: 2010-09-09
Description: RDS Storage Encrypted
Parameters:
  SourceDBInstanceIdentifier:
    Type: String
  DBInstanceType:
    Type: String
  SourceRegion:
    Type: String
Resources:
  MyDBSmall:
    Type: "AWS::RDS::DBInstance"
    Properties:
      DBInstanceClass: !Ref DBInstanceType
      SourceDBInstanceIdentifier: !Ref SourceDBInstanceIdentifier
      SourceRegion: !Ref SourceRegion
      DeletionProtection: false
      KmsKeyId: !Ref MyKey
      EnableIAMDatabaseAuthentication: false

IAM database authentication is not enabled for the replica.

After

yaml
AWSTemplateFormatVersion: 2010-09-09
Description: RDS Storage Encrypted
Parameters:
  SourceDBInstanceIdentifier:
    Type: String
  DBInstanceType:
    Type: String
  SourceRegion:
    Type: String
Resources:
  MyDBSmall:
    Type: "AWS::RDS::DBInstance"
    Properties:
      DBInstanceClass: !Ref DBInstanceType
      SourceDBInstanceIdentifier: !Ref SourceDBInstanceIdentifier
      SourceRegion: !Ref SourceRegion
      DeletionProtection: false
      KmsKeyId: !Ref MyKey
      EnableIAMDatabaseAuthentication: true

IAM authentication is enabled for the replica. Also verify token generation and actual database connections from the application.

References