ã¿ãã§ã.
ã¢ã«ã¦ã³ãã®éç¨ã§ IAM ã¦ã¼ã¶ã¼ã®ãã¹ã¯ã¼ããããªã·ã¼ã«åãã¦å¤æ´ããã¦ãªãã ã MFA æå¹åããªããã°ãªããªãã®ã«æå¹åãããªãã§æ¾ç½®ããã¦ããç宿çã«æ£å¸ããã¦ãããã¨æãã¾ã.
ä»åã¯IAM ã¦ã¼ã¶ã¼ã®æ£å¸ãã«å½¹ç«ã¤, IAM ã®ãèªè¨¼æ å ±ã¬ãã¼ããã¨ããæ©è½ãç´¹ä»ãã¾ã.
AWSããã¥ã¡ã³ã
èªè¨¼æ å ±ã¬ãã¼ãã¨ã¯
ãèªè¨¼æ å ±ã¬ãã¼ããã¨ã¯ IAM ã¦ã¼ã¶ã¼ã®å種èªè¨¼æ å ± (ãã¹ã¯ã¼ã,ã¢ã¯ã»ã¹ãã¼,MFA ããã¤ã¹ãªã©) ã®è¨å®ç¶æ³ãã¬ãã¼ãã¨ãã¦åºåãã¦ãããæ©è½ã§ã.ã¬ãã¼ãã¯4æéãã¨ã«1åçæããã¦ããã®ã§,ææ°ã®ã¬ãã¼ãã§ã¯éå»4æé以å ã®ã¬ãã¼ããå©ç¨è ã¯å ¥æå¯è½ã§ã.
ã¬ãã¼ãã®é ç®
ãèªè¨¼æ å ±ã¬ãã¼ããã®é ç®ãã©ã®ããã«ãªã£ã¦ãããã§ãã,次ã®é ç®ãããã¾ã.
ã«ã©ã å | 説æ |
---|---|
user | ã¦ã¼ã¶ã¼å |
arn | IAMã¦ã¼ã¶ã¼ã®ARN |
user_creation_time | ã¦ã¼ã¶ã¼ã使ãããæ¥æ (ISO 8601 æ¥ä»/æå»å½¢å¼) |
password_enabled | ã¦ã¼ã¶ã¼ããã¹ã¯ã¼ããæã£ã¦ããå ´åTRUE ãã以å¤ã®å ´å㯠FALSE AWS ã¢ã«ã¦ã³ãã®ã«ã¼ãã¦ã¼ã¶ã¼ã¯ not_supported |
password_last_used | ã«ã¼ãã¦ã¼ã¶ã¼ã¾ã㯠IAM ã¦ã¼ã¶ã¼ã®ãã¹ã¯ã¼ãã使ç¨ãã¦æå¾ã« AWS ã¦ã§ããµã¤ãã«ãµã¤ã³ã¤ã³ããæ¥æ |
password_last_changed | ã¦ã¼ã¶ã¼ã®ãã¹ã¯ã¼ããæå¾ã«è¨å®ãããæ¥æ ã¦ã¼ã¶ã¼ããã¹ã¯ã¼ããææãã¦ããªãå ´å, N/A (該å½ãªã) ã«ã¼ãã¦ã¼ã¶ã¼ã¯ not_supported |
password_next_rotation | ãã¹ã¯ã¼ãã®æ´æ°ãå¿
è¦ã¨ãããã¹ã¯ã¼ãããªã·ã¼ãããå ´å,æ°ãããã¹ã¯ã¼ããè¨å®ããããã®ã¦ã¼ã¶ã¼ã«æ±ããæ¥æ ã«ã¼ãã¦ã¼ã¶ã¼ã¯ not_supported |
mfa_active | MFA ãæå¹ãªå ´å,TRUE ç¡å¹ãªå ´å, FALSE |
access_key_1_active | ã¦ã¼ã¶ã¼ãã¢ã¯ã»ã¹ãã¼ãææãã¢ã¯ã»ã¹ãã¼ã®ã¹ãã¼ã¿ã¹ã Active ã§ããå ´åTRUE ãã以å¤ã®å ´å㯠FALSE |
access_key_1_last_rotated | ã¢ã¯ã»ã¹ãã¼ã使ã¾ãã¯æå¾ã«å¤æ´ãããæ¥æ ã¢ã¯ã»ã¹ãã¼ãææãã¦ããªãå ´å N/A |
access_key_1_last_used_date | AWS API ãªã¯ã¨ã¹ãã«ã¦ã¼ã¶ã¼ã®ã¢ã¯ã»ã¹ãã¼ã使ç¨ãããã¨ãã® ISO 8601 æ¥ä»/æå»å½¢å¼ã®æ¥ä»ã¨æå» |
access_key_1_last_used_region | ã¢ã¯ã»ã¹ãã¼ã使ç¨ããããªã¼ã¸ã§ã³ |
access_key_1_last_used_service | ã¢ã¯ã»ã¹ãã¼ã使ç¨ãã¦æè¿ã¢ã¯ã»ã¹ããã AWS ãµã¼ãã¹ |
access_key_2_active | ã¦ã¼ã¶ã¼ã 2 ã¤ç®ã®ã¢ã¯ã»ã¹ãã¼ãææã,ãã® 2 ã¤ç®ã®ãã¼ã®ã¹ãã¼ã¿ã¹ãActive ã§ããå ´åTRUE ãã以å¤ã®å ´å FALSE |
access_key_2_last_rotated | ã¦ã¼ã¶ã¼ã® 2 ã¤ç®ã®ã¢ã¯ã»ã¹ãã¼ã使ã¾ãã¯æå¾ã«å¤æ´ãããæ¥æ |
access_key_2_last_used_date | AWS API ãªã¯ã¨ã¹ãã«ã¦ã¼ã¶ã¼ã® 2 ã¤ç®ã®ã¢ã¯ã»ã¹ãã¼ãç´è¿ã«ä½¿ç¨ãããã¨ãã® ISO 8601 æ¥ä»/æå»å½¢å¼ã®æ¥ä»ã¨æå» |
access_key_2_last_used_region | ã¦ã¼ã¶ã¼ã® 2 ã¤ç®ã®ã¢ã¯ã»ã¹ãã¼ãç´è¿ã«ä½¿ç¨ããããªã¼ã¸ã§ã³ |
access_key_2_last_used_service | ã¦ã¼ã¶ã¼ã® 2 ã¤ç®ã®ã¢ã¯ã»ã¹ãã¼ã使ç¨ãã¦æè¿ã¢ã¯ã»ã¹ããã AWS ãµã¼ãã¹ |
cert_1_active | ã¦ã¼ã¶ã¼ã X.509 ç½²åè¨¼ææ¸ãææããã®è¨¼ææ¸ã®ã¹ãã¼ã¿ã¹ãActive ã§ããå ´åTRUE ãã以å¤ã®å ´å FALSE |
cert_1_last_rotated | ã¦ã¼ã¶ã¼ã®ç½²åè¨¼ææ¸ã使ã¾ãã¯æå¾ã«å¤æ´ãããæ¥æ |
cert_2_active | ã¦ã¼ã¶ã¼ã2ã¤ç®ã® X.509 ç½²åè¨¼ææ¸ãææããã®è¨¼ææ¸ã®ã¹ãã¼ã¿ã¹ãActive ã§ããå ´åTRUE ãã以å¤ã®å ´å FALSE |
cert_2_last_rotated | ã¦ã¼ã¶ã¼ã®2ã¤ç®ã®ç½²åè¨¼ææ¸ã使ã¾ãã¯æå¾ã«å¤æ´ãããæ¥æ |
AWSããã¥ã¡ã³ã
èªè¨¼æ å ±ã¬ãã¼ãçææ¹æ³
åæã¨ãã¦ä»¥ä¸ã®æ¨©éãã¬ãã¼ãã®çæã«å¿ è¦ã§ã.
- èªè¨¼æ å ±ã¬ãã¼ãã使çæãã : GenerateCredentialReport
- ã¬ãã¼ãããã¦ã³ãã¼ããã : GetCredentialReport
AWS ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ããçææ¹æ³
ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ããã®çææ¹æ³ã¯ä»¥ä¸ã®éãã§ã.
1, IAMã®ç»é¢ãããèªè¨¼æ å ±ã¬ãã¼ãã ã鏿ãã¾ã.
2, ãã¬ãã¼ãããã¦ã³ãã¼ãã ã鏿ããã¨,ãstatus_reports_YYYY-MM-DD THH-MM-DD+SS-SS(ISO 8601 æ¥ä»/æå»å½¢å¼).csvããã¡ã¤ã«ããã¦ã³ãã¼ãããã¾ã.
ã¾ã¨ã
IAM ã®ãèªè¨¼æ å ±ã¬ãã¼ããã®æ¦è¦ã¨ã¬ãã¼ãã®é ç®,ãã®çææ¹æ³ãã¾ã¨ãã¾ãã.IAM 㯠AWS ã®æ¨©é管çã®åºç¤ã¨ãªãã¾ãã®ã§,çµç¹ã®éç¨æ¹éã«æ²¿ã£ã管çãã§ãã¦ãããã宿çã«ç¢ºèªããææã¨ãã¦æ´»ãããã¬ãã¼ãã§ã.éç¨ã§ IAM ã¦ã¼ã¶ã¼ãæ£å¸ããå¿ è¦ãããå ´å,ãèªè¨¼æ å ±ã¬ãã¼ããã®å©ç¨ãæ¤è¨ãã¦ã¿ã¦ãããã§ããããï¼
ãªã,ã¬ãã¼ãã«é¢ä¿ãããã¹ã¯ã¼ãããªã·ã¼ã¯ IAM ã®ã¡ãã¥ã¼ã®ãã¢ã«ã¦ã³ãè¨å®ããã確èªå¯è½ã§ã.
AWS ããã¥ã¡ã³ã docs.aws.amazon.com