π‘οΈ Azure Key Vault Certificate Validity Period (in months) is more than 12π’
- Contextual name: π‘οΈ Key Vault Certificate Validity Period (in months) is more than 12π’
- ID:
/ce/ca/azure/key-vault/sertificate-validity-period - Tags:
- π’ Policy with categories
- π’ Policy with type
- π’ Production policy
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY
Logicβ
- π§ prod.logic.yamlπ’
Descriptionβ
Descriptionβ
This policy identifies Azure Key Vault Certificates that are valid for more that 12 months. Restrict the validity period of certificates stored in Azure Key Vault to 12 months or less.
Rationaleβ
Limiting certificate validity reduces the risk of misuse if compromised and helps ensure timely renewal, improving security and reliability.
Impactβ
Minor administrative effort required to ensure certificate renewal and lifecycle management.
Auditβ
This policy flags an Azure Key Vault Certificate as
INCOMPLIANTifValidity Period (in months)is set to more than 12.Default Valueβ
Validity Period (in months)is set to 12 by default.Referencesβ
Remediationβ
Remediationβ
From Azure Portalβ
- Go to
Key vaults.- Click the name of a key vault.
- Under
Objects, clickCertificates.- Click the name of a certificate.
- Click
Issuance Policy.- Set
Validity Period (in months)to an integer between 1 and 12, inclusive.- Click
Save.- Repeat steps 1-7 for each key vault and certificate requiring remediation.
From PowerShellβ
For each certificate requiring remediation, run the following command to set
ValidityInMonthsto an integer between 1 and 12, inclusive:Set-AzKeyVaultCertificatePolicy `
-VaultName $vault.VaultName `
-Name {{certificate-name}} `
-ValidityInMonths {{validity-in-months}}
policy.yamlβ
Linked Framework Sectionsβ
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| πΌ CIS Azure v5.0.0 β πΌ 8.3.11 Ensure certificate 'Validity Period (in months)' is less than or equal to '12' (Automated) | 1 | no data | |||
| πΌ Cloudaware Framework β πΌ Secure Access | 67 | no data |