データベースクラスターの IAM 認証が未使用

対応するデータベースクラスターで IAM 認証を設定し、長期パスワードの共有を減らします。

説明

対応する RDS または Aurora クラスターで IAM データベース認証を使うと、アプリケーションは長期パスワードの代わりに認証トークンで接続できます。この方式を使わず複数のサービスでパスワードを共有すると、更新やアクセス権の管理が難しくなることがあります。IAM 認証の有効化だけで MFA やデータベース監査ログが自動的に有効になるわけではありません。

想定される影響

共有パスワードや長期間使うパスワードが漏えいすると、そのデータベースユーザーの権限でデータにアクセスされるおそれがあります。

対処方法

クラスターのエンジンとバージョンの対応を確認し、EnableIAMDatabaseAuthentication: true を設定してください。IAM 認証用のデータベースユーザー、必要な rds-db:connect 権限、TLS を構成し、アプリケーションのトークン認証を試してください。データベース権限を最小限にし、不要なパスワード利用を廃止してください。

例

Aurora PostgreSQL クラスターの抜粋です。対応する DBEngineVersion と、そのバージョンに適合する DBClusterParameterGroupName を指定してください。ユーザー・パスワードの入力やネットワークなどの定義は省略しています。

変更前

yaml
AWSTemplateFormatVersion: "2010-09-09"
Resources:
  sample:
    Type: "AWS::RDS::DBCluster"
    Properties:
      MasterUsername: !Ref DBUsername
      MasterUserPassword: !Ref DBPassword
      StorageEncrypted: true
      DBClusterIdentifier: aurora-postgresql-cluster
      Engine: aurora-postgresql
      EngineVersion: !Ref DBEngineVersion
      DBClusterParameterGroupName: !Ref DBClusterParameterGroupName
      EnableCloudwatchLogsExports:
        - postgresql
      EnableIAMDatabaseAuthentication: false

クラスターの IAM 認証を無効にしています。他の認証方式の認証情報は引き続き管理が必要です。

変更後

yaml
AWSTemplateFormatVersion: "2010-09-09"
Resources:
  sample:
    Type: "AWS::RDS::DBCluster"
    Properties:
      MasterUsername: !Ref DBUsername
      MasterUserPassword: !Ref DBPassword
      StorageEncrypted: true
      DBClusterIdentifier: aurora-postgresql-cluster
      Engine: aurora-postgresql
      EngineVersion: !Ref DBEngineVersion
      DBClusterParameterGroupName: !Ref DBClusterParameterGroupName
      EnableCloudwatchLogsExports:
        - postgresql
      EnableIAMDatabaseAuthentication: true

クラスターで IAM 認証を利用できるようにします。この設定だけで、既存のすべてのアカウントやアプリケーションの認証方式が切り替わるわけではありません。

参考資料