aws / aws/amazon-ssm-agent

method to gate ssm start-session on an additional Yubikey 2FA authorization

Open
#395 1 comment 3 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
1.2k
Forks
357
PR merge metrics
No merged PRs in 30d

Description

Hi. I've been trying to replace SSH with SSM start-session in our environment because I want the additional logging and detection/response benefits. However, for our production systems, we currently require a Yubikey 2FA authorization on every SSH login. I cannot find an equivalent way to accomplish this security control via SSM start-session. We have tried adding a linux login script to enforce it, but the session can still be started if that script fails. Is there any way to accomplish this? **If there is not an existing method that I missing, would you be open to a pull request to add this capability to the agent if we developed it?** Sorry for the "issue", but I wanted to make sure you were open to the idea before I invested resources in it.

Please note: requiring 2FA in the IAM policy is not a sufficient replacement for our purposes. The security control needs to be an explicit 2FA authorization upon every SSM amazon-ssm-agent to the instance/container. The attack vector being guarded against is an assume client endpoint compromise, so the AWS tokens are assumed stolen off the client endpoint from ~/.aws/credentials or similar .

Contributor guide

Open the contributing guide

Research direction

The issue names no files, tests, or entry points. Start by tracing how SSM start-session authorization reaches the agent and how session startup failures are handled, then review AWS and agent documentation for an explicit per-session YubiKey authorization mechanism. Done should be a clearly scoped, maintainable capability with security tests covering failed and successful authorizations.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, go
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.