AWS Security ChangesHomeSearch

AWS mgn: Added credential security warning for command-line parameters

Service: mgn · 2026-08-31 · Security-related high

File: mgn/latest/ug/linux-agent.md · Type: credentials

Summary

Added guidance to avoid credential exposure via command-line parameters by recommending environment variables with temporary STS credentials.

Security assessment

Explicitly warns about credential exposure via process listing, recommending secure alternatives to prevent unauthorized access.

Evidence

Credentials that you pass as command-line parameters are visible to other users on the source server through the process list (for example, through the `ps` command).

Diff

diff --git a/mgn/latest/ug/linux-agent.md b/mgn/latest/ug/linux-agent.md
index 8160f430a..5cfd151f1 100644
--- a//mgn/latest/ug/linux-agent.md
+++ b//mgn/latest/ug/linux-agent.md
@@ -169,0 +170,8 @@ The installer confirms that the installation of the AWS Replication Agent has st
+If you want to install the Agent without answering the interactive prompts, you can pass your credentials to the installer through environment variables instead. We recommend that you use temporary credentials from AWS Security Token Service (AWS STS). First, set the `AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`, and `AWS_SESSION_TOKEN` environment variables. Then, run the installer with the `sudo -E` command (to preserve the environment variables) and the `--no-prompt` option. For example:
+    
+        export AWS_ACCESS_KEY_ID=AKIAIOSFODNN7EXAMPLE
+    export AWS_SECRET_ACCESS_KEY=wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
+    export AWS_SESSION_TOKEN=AQoDYXdzEJr//////////wEa8AMDSomethingEXAMPLE
+    chmod +x aws-replication-installer-init
+    sudo -E ./aws-replication-installer-init --region us-east-1 --no-prompt
+
@@ -172 +180,10 @@ The installer confirms that the installation of the AWS Replication Agent has st
-     * You can also enter these values as part of the installation script command parameters. If you do not enter these parameters as part of the installation script, you are prompted to enter them one by one as described above. (for example: `sudo chmod +x aws-replication-installer-init; sudo ./aws-replication-installer-init --region regionname --aws-access-key-id AKIAIOSFODNN7EXAMPLE --aws-secret-access-key wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY`).
+     * You can also pass the AWS Access Key ID and AWS Secret Access Key as command-line parameters. In the following example, replace `<region>` with the AWS Region into which you are replicating:
+        
+                sudo chmod +x aws-replication-installer-init
+        sudo ./aws-replication-installer-init --region <region> --aws-access-key-id AKIAIOSFODNN7EXAMPLE --aws-secret-access-key wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
+
+###### Warning
+
+Credentials that you pass as command-line parameters are visible to other users on the source server through the process list (for example, through the `ps` command). To avoid exposing your credentials, use the environment variable method described in the previous step. If you do pass credentials as command-line parameters, use temporary credentials from AWS STS and rotate them after installation.
+
+     * If you do not enter these parameters as part of the installation script, you are prompted to enter them one by one as described in the previous step.