2017-04-29 23:46:53 +00:00
|
|
|
mfa_not_enabled_user = attribute(
|
|
|
|
'mfa_not_enabled_user',
|
|
|
|
default: 'default.mfa_not_enabled_user',
|
|
|
|
description: 'Name of IAM user mfa_not_enabled_user')
|
|
|
|
|
|
|
|
console_password_enabled_user = attribute(
|
|
|
|
'console_password_enabled_user',
|
|
|
|
default: 'default.console_password_enabled_user',
|
|
|
|
description: 'Name of IAM user console_password_enabled_user')
|
|
|
|
|
2017-06-13 05:36:43 +00:00
|
|
|
access_key_user = attribute(
|
|
|
|
'access_key_user',
|
|
|
|
default: 'default.access_key_user',
|
|
|
|
description: 'Name of IAM user access_key_user')
|
|
|
|
|
2017-04-29 23:46:53 +00:00
|
|
|
describe aws_iam_user(mfa_not_enabled_user) do
|
2017-06-13 05:36:43 +00:00
|
|
|
it { should_not have_mfa_enabled }
|
|
|
|
it { should_not have_console_password }
|
2017-04-29 23:46:53 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
describe aws_iam_user(console_password_enabled_user) do
|
2017-06-13 05:36:43 +00:00
|
|
|
it { should have_console_password }
|
|
|
|
end
|
|
|
|
|
|
|
|
aws_iam_user(access_key_user).access_keys.each { |access_key|
|
|
|
|
describe access_key do
|
|
|
|
it { should be_active }
|
|
|
|
end
|
|
|
|
}
|