5 ms·
Feels odd that AWS still uses secret tokens all these years later. Take GCP for example. They use your personal identity (via OAuth, service accounts use certs)
by twistedpair 5y ago
Feels odd that AWS still uses secret tokens all these years later. Take GCP for example. They use your personal identity (via OAuth, service accounts use certs), and you can use FIDO tokens to authenticate your local keys (e.g. for gcloud CLI). I was very surprised to see that awscli still doesn't support Yubikeys.
- jffry 5y agoI'm a big fan of aws-vault [1], which helps securely store your tokens and use them to obtain temporary credentials which are time-limited and constrained to a specific IAM role. It's not as good as having something that supports a hardware token, of course, but it's better than the default awscli suggestion to keep the secrets around in plaintext either on disk or in env vars. [1] https://github.com/99designs/aws-vault https://github.com/99designs/aws-vault
- tptacek 5y agoaws-vault is one of the standard answers for this problem, and once you have it set up, the ergonomics are in some ways superior to that of manually managed AWS secrets. Highly recommended.
- deleted 5y ago[deleted]
- moltar 5y agoYou can use SSO with aws-vault
- 0xbadcafebee 5y agoOr, use saml2aws with your system keychain (pass/gpg for headless systems) and don't use aws-vault at all. With the credential_process option to AWS CLI, you don't even ever need to re-authenticate, as the AWS CLI will call saml2aws, which will use your keychain-stored SSO credentials, and automatically refresh your AWS temporary session.
- OJFord 5y ago> I was very surprised to see that awscli still doesn't support Yubikeys. Singular it does, per IAM user.
- drodgers 5y agoBut only for the web console, not via the CLI. The API for generating short-term keys (which aws-vault uses) only supports TOTP, not FIDO/U2F/WebAuthn. https://github.com/aws/aws-cli/issues/3607 https://github.com/aws/aws-cli/issues/3607
- OJFord 5y agoSure, but I was responding to 'Yubikey', not about any specific protocol. I'm not claiming it's ideal, but it works, with one Yubikey per IAM user: https://aws.amazon.com/premiumsupport/knowledge-center/authenticate-mfa-cli/ https://aws.amazon.com/premiumsupport/knowledge-center/authe...
- twistedpair 5y ago> I was very surprised to see that awscli still doesn't support Yubikeys Thanks, but you cannot[0] use hardware keys on the terminal. [0] https://github.com/aws/aws-cli/issues/3607 https://github.com/aws/aws-cli/issues/3607
- OJFord 5y agoThat's about U2F, which is just one protocol that (most) Yubikeys support.