Information
Ensure that all Secrets in Azure Key Vaults using Role Based Access Control (RBAC) have an expiration date set.
Note: The audit commands require data-plane access to each Key Vault in addition to themanagement-plane Reader role. Without data-plane access these commands return empty results silently.
The Azure Key Vault enables users to store and keep secrets within the Microsoft Azure environment. Secrets in the Azure Key Vault are octet sequences with a maximum size of 25k bytes each. The exp (expiration date) attribute identifies the expiration date on or after which the secret MUST NOT be used. By default, secrets never expire. It is thus recommended to rotate secrets in the key vault and set an explicit expiration date for all secrets. This ensures that the secrets cannot be used beyond their assigned lifetimes.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.
Solution
Requisite RBAC Permissions for Secrets - read section overview!
Remediation Role = Key Vault Secrets Officer
Remediate from Azure Portal
- Go to Key vaults.
- For each Key vault, under Objects, select Secrets.
- In the main pane, ensure that the status of the secret(s) is Enabled.
- Click on the secret(s) without Expiration date.
- Click on the current version secret
- Click the checkbox Set expiration date and set an appropriate Expiration date on the secret.
- Click Apply.
Remediate from Azure CLI
Update the Expiration date for the secret using the below command:
az keyvault secret set-attributes --name <secret_name> --vault-name <vault_name> --expires Y-m-d'T'H:M:S'Z'
Remediate from PowerShell
Set-AzKeyVaultSecretAttribute -VaultName <vault_name> -Name <secret_name> -Expires <date_time>
Impact:
Secrets cannot be used beyond their assigned expiry date respectively. Secrets need to be rotated periodically wherever they are used.