Cloudflare Access encryption, keys & secrets security checks
Encryption at rest and in transit, key rotation, and the API keys, tokens and credentials that outlive the people who created them.
On Cloudflare Access, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Cloudflare Access connector needs.
Checks (3)
severity: high Service Token Without Expiry fix difficulty: medium #
Set an expiration date on the Cloudflare Access service token to limit credential exposure
- Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
- Navigate to Access > Service Auth > Service Tokens
- Locate the service token without an expiry date
- Click the token to edit it and set an expiration date (recommended: 1 year or less)
- Save the token and update consuming services with the new token if it was regenerated
- Schedule a rotation reminder before the expiry date
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.ii HIPAA (SaaS Security) HIPAA-312.c NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.8
severity: medium Stale Service Token fix difficulty: medium #
Rotate or revoke the Cloudflare Access service token that has not been rotated in over 180 days
- Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
- Navigate to Access > Service Auth > Service Tokens
- Locate the stale service token (last rotated over 180 days ago)
- Click "Refresh" to generate a new client secret for the token
- Update all services and automation that use this token with the new credentials
- Confirm the old token is no longer in use and document the rotation
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.ii HIPAA (SaaS Security) HIPAA-312.c NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.8
severity: low Expired Service Token Not Deleted fix difficulty: easy #
Delete or renew the expired Cloudflare Access service token to remove abandoned credentials
- Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
- Navigate to Access > Service Auth > Service Tokens
- Locate the expired service token
- If the token is no longer needed, click "Delete" and confirm deletion
- If the token is still required, click "Refresh" and set a new expiration date, then update consuming services
- Verify no active services are still attempting to use the expired token
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.ii HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.8