IAM Roles Anywhere now supports modifying the mapping of certificate attributes
Share
Services
[AWS Identity and Access Management (IAM) Roles Anywhere](https://aws.amazon.com/iam/roles-anywhere/) now provides the capability to define a set of mapping rules, allowing you to specify which data is extracted from your X.509 end-entity certificates. The data that is mapped is referred to as attributes and used as session tags in the IAM policy condition in order to allow or deny permissions. These attributes can be in one of the subject, issuer, or subject alternative name (SAN) fields of the X.509 certificate.
By default, all relative distinguished names (RDNs) from the certificate’s subject and issuer are mapped, along with the first value of the domain name system (DNS), directory name (DN), and uniform resource identifier (URI) from the certificate’s SAN. With this launch, you can now define a set of mapping rules and choose only a subset of those certificate’s attributes that meet your business needs. Thus, reducing the size and the complexity of the tags used for the authorization policies. These mapped attributes are associated with your profile. You can define those mapping rules by using the [put-attribute-mapping](https://docs.aws.amazon.com/rolesanywhere/latest/APIReference/API%5FPutAttributeMapping.html) or [delete-attribute-mapping](https://docs.aws.amazon.com/rolesanywhere/latest/APIReference/API%5FDeleteAttributeMapping.html) APIs from the IAM Roles Anywhere console, AWS SDKs, and AWS CLI.
This functionality is supported in all [AWS Regions](https://docs.aws.amazon.com/general/latest/gr/rolesanywhere.html) where IAM Roles Anywhere is available including the AWS GovCloud (US) Regions. To learn more about this functionality, see the [User Guide](https://docs.aws.amazon.com/rolesanywhere/latest/userguide/attribute-mapping.html), [API Reference Guide](https://docs.aws.amazon.com/rolesanywhere/latest/APIReference/), and [AWS CLI Reference](https://docs.aws.amazon.com/cli/latest/reference/rolesanywhere/).
What else is happening at Amazon Web Services?
Amazon Bedrock now available in the Asia Pacific (Mumbai) Region
about 17 hours ago
Services
Share
Amazon Personalize launches new recipes supporting larger item catalogs with lower latency
about 21 hours ago
Services
Share
Amazon Connect Contact Lens now provides generative AI-powered agent performance evaluations (preview)
about 21 hours ago
Services
Share
Amazon Chime SDK Voice Connector now supports audio streaming G.711 A-Law encoded audio
about 21 hours ago
Services
Share
Read update
Services
Share