AWS AWSEC2: Minor wording and link updates for IMDSv2 enforcement
Summary
Changed 'via' to 'through' in two sentences, updated a documentation link to relative path, and rephrased a recommendation sentence.
Security assessment
Changes are grammatical (preposition substitution) and documentation formatting (relative vs absolute link), with no impact on security content or vulnerabilities.
Evidence
+Furthermore, you can choose an additional layer of protection to enforce the change from IMDSv1 to IMDSv2. At the access management layer with respect to the APIs called through EC2 Role credentials, you can use a condition key in either IAM policies or AWS Organizations service control policies (SCPs). Specifically, by using the condition key `ec2:RoleDelivery` with a value of `2.0` in your IAM policies, API calls made with EC2 Role credentials obtained from IMDSv1 will receive an `UnauthorizedOperation` response. The same thing can be achieved more broadly with that condition required by an SCP. This ensures that credentials delivered through IMDSv1 cannot actually be used to call APIs because any API calls not matching the specified condition will receive an `UnauthorizedOperation` error.
Diff
diff --git a/AWSEC2/latest/UserGuide/instance-metadata-transition-to-version-2.md b/AWSEC2/latest/UserGuide/instance-metadata-transition-to-version-2.md index 9fa78e56a..1784792af 100644 --- a//AWSEC2/latest/UserGuide/instance-metadata-transition-to-version-2.md +++ b//AWSEC2/latest/UserGuide/instance-metadata-transition-to-version-2.md @@ -116 +116 @@ If a parameter in the API or CLI call doesn't match the state specified in the p -Furthermore, you can choose an additional layer of protection to enforce the change from IMDSv1 to IMDSv2. At the access management layer with respect to the APIs called via EC2 Role credentials, you can use a condition key in either IAM policies or AWS Organizations service control policies (SCPs). Specifically, by using the condition key `ec2:RoleDelivery` with a value of `2.0` in your IAM policies, API calls made with EC2 Role credentials obtained from IMDSv1 will receive an `UnauthorizedOperation` response. The same thing can be achieved more broadly with that condition required by an SCP. This ensures that credentials delivered via IMDSv1 cannot actually be used to call APIs because any API calls not matching the specified condition will receive an `UnauthorizedOperation` error. +Furthermore, you can choose an additional layer of protection to enforce the change from IMDSv1 to IMDSv2. At the access management layer with respect to the APIs called through EC2 Role credentials, you can use a condition key in either IAM policies or AWS Organizations service control policies (SCPs). Specifically, by using the condition key `ec2:RoleDelivery` with a value of `2.0` in your IAM policies, API calls made with EC2 Role credentials obtained from IMDSv1 will receive an `UnauthorizedOperation` response. The same thing can be achieved more broadly with that condition required by an SCP. This ensures that credentials delivered through IMDSv1 cannot actually be used to call APIs because any API calls not matching the specified condition will receive an `UnauthorizedOperation` error. @@ -168 +168 @@ Use the [describe-instances](https://awscli.amazonaws.com/v2/documentation/api/l -Use the CloudWatch metric `MetadataNoToken`. This metric shows the number of IMDSv1 calls to the IMDS on your instances. For more information, see [Instance metrics](https://docs.aws.amazon.com/en_us/AWSEC2/latest/UserGuide/viewing_metrics_with_cloudwatch.html#ec2-cloudwatch-metrics). +Use the CloudWatch metric `MetadataNoToken`. This metric shows the number of IMDSv1 calls to the IMDS on your instances. For more information, see [Instance metrics](./viewing_metrics_with_cloudwatch.html#ec2-cloudwatch-metrics). @@ -281 +281 @@ Use a Declarative Policy to set the organization default for IMDSv2 to required. -Once you’ve confirmed that there is no dependency on IMDSv1 on any of your instances, we recommend that you enforce IMDSv2 on all new instances. +After you’ve confirmed that there is no dependency on IMDSv1 on any of your instances, we recommend that you enforce IMDSv2 on all new instances.