Identify what SES calls are using version 2 signature logins

Viewed 590

Like many I'm sure, we've received an email from Amazon stating: We recently observed Signature Version 2 requests on an Amazon SES SMTP endpoint originating from your account.

Is there any way to identify what these calls are as we have several IAM users and large codebases and haven't yet been able to trace the origin of these calls.

I'm thinking this should be possible with CloudWatch/CloudTrail but can't see how to do this.

2 Answers

From a question in the AWS dev forum

If your existing smtp credentials were created via console, the creation date (visible in IAM console) can be an indication of Signature v2 usage, as smtp users created via the SES console before Feb 2019 were Signature v2 signed. Credentials created in the SES console after this date are signed using Signature v4.

You can't use CloudTrail to audit SES send events because SES only delivers management events to CloudTrail, as mentioned here.

You can't use SES event publishing because it doesn't contain the request details that triggered the send.

As mentioned on this AWS forum thread, according to an AWS representative they are working on a way to track SigV2 usage, however that's not too helpful considering they will begin to throttle SigV2 requests in 10 days.

So currently, the best way to identify credentials still using SigV2 is to:

  • Regenerate all credentials created in the SES console
  • Generate SigV4 SES credentials from all IAM credentials that may be using SES and compare them to the SES credentials that you are actually using.
Related