Description
Broad iam:CreateAccessKey permission can let a role user issue a new access key for another IAM user and call APIs with that user’s permissions. Target-user restrictions and effective policies still govern issuance and use.
Creating a key for a more privileged user can provide long-term credentials that enable privilege misuse.
Potential impact
- Impersonation of a privileged user: the new key can authorize operations allowed for its owner.
- Persistent credentials: an issued key can remain available for continued misuse.
- Delayed detection: unauthorized issuance can be hard to distinguish from legitimate administration.
Remediation
- Remove
iam:CreateAccessKeyfrom roles that do not manage keys. - Restrict required issuance to dedicated administrators and approved target users.
- Monitor key creation and prefer role-based temporary credentials where possible.
Examples
These are permission-policy excerpts. Configure the role’s trust policy separately.
Before
hcl
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "test_inline_policy"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:CreateAccessKey",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
After
hcl
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "inline_policy_run_instances"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
The after example removes key issuance from this policy on the same role and leaves EC2 describe permissions. Review other attached policies and keys already issued separately.