Federation

Federation lets an external identity provider mint AWS role credentials without an IAM user. The trust is declared by an IAM identity provider object plus a role whose trust policy accepts tokens from it, scoped by Condition on claims such as sub and aud. When those conditions are loose, an attacker who controls or can forge a matching token assumes the role.

What folds in here#

  • SAML: sts:AssumeRoleWithSAML and over-broad SAML provider trust.
  • OIDC: sts:AssumeRoleWithWebIdentity and weak sub/aud conditions on an OIDC provider.
  • GitHub Actions: the GitHub OIDC provider with a sub condition loose enough to accept other repositories or branches.
  • Trusted IdP: third-party IdPs (Auth0, Okta, Google) trusted as web-identity providers.
  • Roles Anywhere: X.509 certificate trust that mints role credentials outside AWS.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more