fixinventory icon indicating copy to clipboard operation
fixinventory copied to clipboard

AWS user missing mtime

Open lloesche opened this issue 3 years ago • 4 comments

Description

A user's atime should be the time the account was last used, a users mtime should be the time the password was last updated. The new AWS collector is missing this info.

Version

main

Environment

No response

Steps to Reproduce

No response

Logs

No response

Additional Context

No response

lloesche avatar Aug 20 '22 04:08 lloesche

ctime is mapped from CreateDate atime is mapped from PasswordLastUsed mtime is not mapped - the same as the old collector.

For PasswordLastUsed AWS writes this:

If the value is missing, then the user either has no password or the password has not been used since IAM began tracking password age on October 20, 2014.

So we could use either PasswordLastUsed and/or the last used AccessKey for atime. If nothing is present we could fallback to October 2014. wdyt?

Not sure if there is a meaningful property for mtime?

aquamatthias avatar Aug 23 '22 12:08 aquamatthias

Let's not mix IAM User objects with their AccessKey. Let's stick to PasswordLastUsed and let's also not fall back to 2014. Chances are users simply haven't used the account using password login when PasswordLastUsed is not set.

lloesche avatar Aug 30 '22 12:08 lloesche

Trying to poke my nose here, can someone explain me more about how I can check atime/mtime for a user & help fix this bug?

kushthedude avatar Sep 07 '22 19:09 kushthedude

Then I think the handling of atime is correct, but mtime is missing. Will adjust the title.

aquamatthias avatar Sep 08 '22 11:09 aquamatthias

@lloesche @aquamatthias I've been looking into this and am not convinced that this information is available at all. I found this AWS Security Blogpost where they mention the property password_last_rotated as part of a credentials report. That would map nicely to our mtime. And supposedly all these entries are available via API as well. But the blog post is from 2014 and in no IAM documentation have I found any reference to this property whatsoever. So I'm not convinced it's in use any longer 🤷🏻‍♀️ image

anjafr avatar Oct 21 '22 12:10 anjafr

Closing this issue for now. Would reopen it once we have specific requests to pull such data.

aquamatthias avatar Nov 04 '22 15:11 aquamatthias