Description
Without IAM database authentication, applications may rely on separately managed database credentials. Supported RDS for MariaDB, MySQL and PostgreSQL instances can accept IAM authentication tokens. A token is valid for authenticating new connections for 15 minutes; it does not limit the lifetime of an established session.
Potential impact
Storing or sharing long-term passwords across systems can increase the risk of exposure and missed access revocation.
Remediation
Check engine, version and application support, then set EnableIAMDatabaseAuthentication: true. Configure a database user for IAM authentication, the required rds-db:connect permission and a TLS connection. Manage database privileges and audit logs separately. For Aurora, configure IAM authentication on the cluster rather than the instance.
Examples
These excerpts assume a read replica of an encrypted RDS MySQL source. Supply its identifier and Region, a supported instance class and a usable KMS key through the omitted MyKey definition.
Before
AWSTemplateFormatVersion: 2010-09-09
Description: RDS Storage Encrypted
Parameters:
SourceDBInstanceIdentifier:
Type: String
DBInstanceType:
Type: String
SourceRegion:
Type: String
Resources:
MyDBSmall:
Type: "AWS::RDS::DBInstance"
Properties:
DBInstanceClass: !Ref DBInstanceType
SourceDBInstanceIdentifier: !Ref SourceDBInstanceIdentifier
SourceRegion: !Ref SourceRegion
DeletionProtection: false
KmsKeyId: !Ref MyKey
EnableIAMDatabaseAuthentication: false
IAM database authentication is not enabled for the replica.
After
AWSTemplateFormatVersion: 2010-09-09
Description: RDS Storage Encrypted
Parameters:
SourceDBInstanceIdentifier:
Type: String
DBInstanceType:
Type: String
SourceRegion:
Type: String
Resources:
MyDBSmall:
Type: "AWS::RDS::DBInstance"
Properties:
DBInstanceClass: !Ref DBInstanceType
SourceDBInstanceIdentifier: !Ref SourceDBInstanceIdentifier
SourceRegion: !Ref SourceRegion
DeletionProtection: false
KmsKeyId: !Ref MyKey
EnableIAMDatabaseAuthentication: true
IAM authentication is enabled for the replica. Also verify token generation and actual database connections from the application.