Encoded private key in user data

Base64 encoding does not protect a private key stored in user data.

Description

A private key stored in UserData as Base64 can be decoded easily. Encoding is not encryption, and anyone who can read the template or instance user data may obtain the secret.

Potential impact

If the exposed key is used for authentication, its access privileges could be misused.

Remediation

Remove private keys from UserData and revoke and replace exposed keys. If a secret is necessary, retrieve it at runtime from a dedicated store using an instance role with only the required permissions. Keep it out of logs and deployment artifacts.

Examples

These examples use a supported launch template. Supply ImageId and a compatible InstanceType. The original Base64 value imitates a private-key header and is not a real key. The revised example uses Fn::Base64 to encode a startup script containing no secrets.

Before

json
{
  "Parameters": {
    "ImageId": {
      "Type": "AWS::EC2::Image::Id"
    },
    "InstanceType": {
      "Type": "String"
    }
  },
  "Resources": {
    "myLaunchConfig3": {
      "Type": "AWS::EC2::LaunchTemplate",
      "Properties": {
        "LaunchTemplateData": {
          "ImageId": {
            "Ref": "ImageId"
          },
          "InstanceType": {
            "Ref": "InstanceType"
          },
          "UserData": "LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpzb21lS2V5"
        }
      }
    }
  }
}

After

json
{
  "Parameters": {
    "ImageId": {
      "Type": "AWS::EC2::Image::Id"
    },
    "InstanceType": {
      "Type": "String"
    }
  },
  "Resources": {
    "myLaunchConfig3": {
      "Type": "AWS::EC2::LaunchTemplate",
      "Properties": {
        "LaunchTemplateData": {
          "ImageId": {
            "Ref": "ImageId"
          },
          "InstanceType": {
            "Ref": "InstanceType"
          },
          "UserData": {
            "Fn::Base64": "#!/bin/sh\necho bootstrap only\n"
          }
        }
      }
    }
  }
}

References