Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GCP "Lack of Service Account Key Rotation" finding raises "SYSTEM_MANAGED" keys #1085

Closed
x4v13r64 opened this issue Feb 17, 2021 · 1 comment
Assignees
Labels
bug Something isn't working component-provider-gcp Affects GCP provider good first issue
Milestone

Comments

@x4v13r64
Copy link
Collaborator

The https://github.com/nccgroup/ScoutSuite/blob/master/ScoutSuite/providers/gcp/rules/findings/iam-lack-of-service-account-key-rotation.json finding should only flag USER_MANAGED keys (https://cloud.google.com/iam/docs/reference/rest/v1/projects.serviceAccounts.keys), as SYSTEM_MANAGED keys are "managed and rotated by Google"

@fernando-gallego
Copy link
Collaborator

Fixed in 5.12.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working component-provider-gcp Affects GCP provider good first issue
Projects
None yet
3 participants