Amazon IAM Key Secret Template for RPC

Overview

This document briefly discusses using Secret Server Remote Password Changing (RPC) for Amazon IAM Key accounts. With Remote Password Changing (RPC), secrets can automatically change remote account passwords when a secret expires, either immediately or on a defined schedule. In addition, the new passwords’ strengths and other qualities are completely configurable. See the Password Changer List for a complete list of available password changers.

Secret Server can scan Amazon Web Services (AWS) for accounts that can access the cloud resource. The secrets based on the “Amazon IAM Key” templates can be discovered and managed through the Secret Server.

An Amazon IAM key secret should be connected to an Amazon IAM console password secret to enable password modification. For details, see Password Management in AWS.

AWS GovCloud Support (Region Field)

The Amazon IAM Key secret template includes a Region field that determines which AWS partition endpoint Secret Server uses for password changing, privileged password changing, and heartbeat:

  • Blank (default): Secret Server uses the commercial AWS partition (iam.amazonaws.com). Existing secrets require no configuration change.

  • us-gov-west-1 or us-gov-east-1: Secret Server uses the AWS GovCloud (US) partition (iam.us-gov.amazonaws.com).

If the Region field contains any other value, the operation fails immediately with an error. Secret Server never falls back to the commercial endpoint when an unrecognized region is specified, ensuring credentials are only ever sent to a validated endpoint.

This applies to both basic and privileged password changing.

AWS China (aws-cn) is not supported.

Assigning a Password Changer to a Secret Template

After completing the RPC setup, you can manage the built-in secret templates. Each secret template is specific application and is preconfigured with the password changer best suited to that. For the Amazon IAM Key, we want the Amazon IAM Key template.

You can view and modify secret templates in the Secret Server administration panel. See Creating or Editing Secret Templates for more on the available options. Ensure that the secret template is in active status. See Activating and Deactivating Templates for details.

To navigate to an Amazon IAM secret template:

  1. Search for Secret Templates. The Secrets Administration page is displayed.

  2. In the Core Actions section, click Secret Templates. The list of available templates is displayed.

  3. Select an Amazon AIM secret template and then click the Mapping tab.

You can check what secret template conforms to the selected RPC. The screenshot below shows that the Amazon IAM Key RPC conforms to the identically titled secret template. It is possible to assign several password changers to one secret template. For more information, see Assigning a Password Changer to a Secret Template.

Secret templates determine the fields, launchers, and the remote password changer for secrets. To utilize the Amazon IAM Key template on a secret, see Managing Secrets.