Medium
IAM
Expired SSL/TLS certificates managed in IAM should be removed
CIS v5.0.0
Description
Flags expired SSL/TLS server certificates still present and active in IAM.
Remediation
To remediate expired IAM server certificates, you need to remove expired SSL/TLS certificates from IAM.
Steps
- Navigate to the AWS IAM console
- Go to 'Certificates' in the left navigation
- Review all server certificates
- Identify expired certificates
- Remove expired certificates from IAM
- Update applications to use valid certificates
- Consider migrating to AWS Certificate Manager (ACM)
- Set up certificate expiration monitoring
- Document certificate removal for audit purposes
- Implement automated certificate lifecycle management
Compliance
CIS v5.0.0