Description
Enabling Neptune IAM database authentication requires AWS Signature Version 4 (SigV4) signatures for data requests and uses IAM policies to control data access. With it disabled, those IAM request-authentication and authorization checks do not apply.
Combine authentication with network restrictions so connectivity alone is not enough for data access. StorageEncrypted protects stored data; it does not authenticate requests.
Potential impact
- Clients that do not need data access but can reach the database may be able to read or change data.
- Compromise of a connected system can expose a data path without IAM-based restrictions.
Remediation
- Prepare SigV4 signing and required
neptune-db:data permissions before settingIamAuthEnabled: true. Distinguish data permissions from management API permissions. - Schedule the change: changing IAM authentication restarts the engine and terminates existing connections.
- Restrict security groups and connection paths to required clients. Test that authorized requests work and unauthorized requests are rejected.
Examples
The examples change authentication on the same cluster. Configure DB instances, subnets, security groups and clients separately.
Before
Resources:
NeptuneDBCluster:
Type: AWS::Neptune::DBCluster
Properties:
IamAuthEnabled: false
StorageEncrypted: true
Storage encryption is enabled, but IAM database authentication is disabled.
After
Resources:
NeptuneDBCluster:
Type: AWS::Neptune::DBCluster
Properties:
IamAuthEnabled: true
StorageEncrypted: true
IAM authentication is enabled. Prepare client request signing and data permissions before applying the change.