Roles Anywhere

IAM Roles Anywhere lets workloads outside AWS obtain role credentials by presenting an X.509 client certificate issued under a configured trust anchor (a CA). If you can obtain or issue a certificate the trust anchor accepts, you mint role credentials from anywhere, no AWS user needed.

Exchanging a certificate for credentials#

bash
aws_signing_helper credential-process \
  --certificate client.pem --private-key client.key \
  --trust-anchor-arn arn:aws:rolesanywhere:...:trust-anchor/<id> \
  --profile-arn arn:aws:rolesanywhere:...:profile/<id> \
  --role-arn arn:aws:iam::<acct>:role/<role>

Exploitation notes#

  • The attack hinges on the CA: control of the trust-anchor CA (or a sub-CA it chains to) lets you issue certificates for any role the profile allows.
  • A leaked client certificate and key are directly reusable until revoked or expired.
  • The profile and role constrain which roles a certificate can assume, so enumerate profiles to see the reachable set.

Tools#

  • aws_signing_helper: the AWS credential helper for Roles Anywhere.
  • Standard PKI tooling (OpenSSL) to inspect or issue certificates.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more