5 ms·
IMDSv2 was initially introduced after the capital one attack. but aws users will have to explicitly enable it and its not enabled by default. now they are chan
by eightnoteight 3y ago
IMDSv2 was initially introduced after the capital one attack. but aws users will have to explicitly enable it and its not enabled by default.
now they are changing the default modes for instances launched from aws console using quick start process. and sometime in 2024 they will give an option to customers to control the default value for all run instances API calls from an account
- colmmacc 3y agoIMDSv2 has been enabled by default since launch, and was made the default in the AWS SDKs at the same time. What's changing now is that IMDSv1 will be disabled by default. Until now customers had to disable it intentionally, either at the instance level, or by using IAM policies / SCPs to block calls still using IMDSv1 issued credentials.
- eightnoteight 3y agoI think we mean different things, it is enabled by default but I'm saying thats not the default IMDS version that metadata endpoint points to for `/latest/` for example if you run below curl request on ec2 instances launched from aws console before nov 6th then you will get a response ```sh curl http://169.254.169.254/latest/meta-data/profile http://169.254.169.254/latest/meta-data/profile ``` but if you run the same command on ec2 instances launched from aws console after nov 6th, then you will get an error that auth token is missing
- colmmacc 3y agoIMDSv2 doesn't change the URLs, the "/latest/" in that URL is referring to the meta-data profile, rather than the IMDS version. IMDS is a lower level change in the authentication workflow to use a token (which is retrieved using a PUT request). https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-metadata-v2-how-it-works.html https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance... has a good example.