Medium IAM

Expired SSL/TLS certificates managed in IAM should be removed

CIS v5.0.0

Description

Flags expired SSL/TLS server certificates still present and active in IAM.


Remediation

To remediate expired IAM server certificates, you need to remove expired SSL/TLS certificates from IAM.

Steps

  1. Navigate to the AWS IAM console
  2. Go to 'Certificates' in the left navigation
  3. Review all server certificates
  4. Identify expired certificates
  5. Remove expired certificates from IAM
  6. Update applications to use valid certificates
  7. Consider migrating to AWS Certificate Manager (ACM)
  8. Set up certificate expiration monitoring
  9. Document certificate removal for audit purposes
  10. Implement automated certificate lifecycle management

Compliance

CIS v5.0.0