An organization uses Vault with AWS IAM auth. After rotating the AWS IAM role credentials, users are unable to authenticate with Vault. The Vault audit logs show 'permission denied' for the AWS auth method. What is the most likely cause?
Trap 1: The IAM role trust policy was not updated after credential rotation
Incorrect. IAM role trust policies do not contain access keys or secret keys; they define which principals are trusted. Rotating credentials does not require trust policy changes.
Trap 2: The Vault token TTL expired
Incorrect. Token TTL expiration affects existing tokens but does not prevent initial authentication via AWS auth method.
Trap 3: The client token used for AWS auth is revoked
Incorrect. The client token referenced here is irrelevant; the error is from the auth method itself, not a specific token.
- A
The IAM role trust policy was not updated after credential rotation
Why it fails: Incorrect. IAM role trust policies do not contain access keys or secret keys; they define which principals are trusted. Rotating credentials does not require trust policy changes.
- B
The Vault token TTL expired
Why it fails: Incorrect. Token TTL expiration affects existing tokens but does not prevent initial authentication via AWS auth method.
- C
The client token used for AWS auth is revoked
Why it fails: Incorrect. The client token referenced here is irrelevant; the error is from the auth method itself, not a specific token.
- D
The AWS secret engine is disabled
Correct. If the AWS secret engine is disabled, Vault cannot process AWS authentication requests, resulting in 'permission denied'.