Neptune cluster has IAM database authentication disabled

Authenticate Neptune data requests with IAM and restrict connectivity to required clients.

Description

Enabling Neptune IAM database authentication requires AWS Signature Version 4 (SigV4) signatures for data requests and uses IAM policies to control data access. With it disabled, those IAM request-authentication and authorization checks do not apply.

Combine authentication with network restrictions so connectivity alone is not enough for data access. StorageEncrypted protects stored data; it does not authenticate requests.

Potential impact

  • Clients that do not need data access but can reach the database may be able to read or change data.
  • Compromise of a connected system can expose a data path without IAM-based restrictions.

Remediation

  • Prepare SigV4 signing and required neptune-db: data permissions before setting IamAuthEnabled: true. Distinguish data permissions from management API permissions.
  • Schedule the change: changing IAM authentication restarts the engine and terminates existing connections.
  • Restrict security groups and connection paths to required clients. Test that authorized requests work and unauthorized requests are rejected.

Examples

The examples change authentication on the same cluster. Configure DB instances, subnets, security groups and clients separately.

Before

yaml
Resources:
  NeptuneDBCluster:
    Type: AWS::Neptune::DBCluster
    Properties:
      IamAuthEnabled: false
      StorageEncrypted: true

Storage encryption is enabled, but IAM database authentication is disabled.

After

yaml
Resources:
  NeptuneDBCluster:
    Type: AWS::Neptune::DBCluster
    Properties:
      IamAuthEnabled: true
      StorageEncrypted: true

IAM authentication is enabled. Prepare client request signing and data permissions before applying the change.

References