KMS key policy permissions need review

Review effective KMS key permissions, restrict access to required users and services, and preserve administration and recovery paths.

Description

A KMS key policy that grants unnecessary principals decryption or key-management permissions can affect data protection and key availability. Separate key-use operations from administration and review the actual key policy, IAM permissions and KMS grants together.

In a key policy, Resource: "*" means the key to which the policy is attached, not every key. Creating a key through the API without a policy applies a default that enables the owning account to delegate access through IAM policies. Do not remove this account delegation or necessary administration solely because it uses a wildcard.

Potential impact

  • Unnecessary effective decryption or management permissions can broaden data access or disrupt services that depend on the key.
  • Removing essential administrative access can prevent future policy changes. Adding a nominal condition does not necessarily restrict access.

Remediation

  1. Identify the actual policy and required users, roles and services. Minimize key-use and administrative permissions separately. In amazon.aws 11.4.0, omitting the policy when managing an existing key preserves its current policy.
  2. Restrict principals and actions with effective conditions. kms:CallerAccount limits the account initiating the request; kms:ViaService limits supported AWS services making requests on a principal's behalf. Test allowed and denied requests using the actual account, Region and service path.
  3. Preserve a path for future kms:PutKeyPolicy calls and do not bypass the lockout safety check. Verify key administration, recovery and required service access after the change.

Examples

Replace my-kms-key with the actual alias. In the after-example, key_account_id is the key-owning account and aws_region is the Region where EC2/EBS uses the key. Preserve required statements from the existing policy, and confirm that the deployment identity retains policy-management access through IAM permissions before applying it.

Before

yaml
- name: Update IAM policy on an existing KMS key
  amazon.aws.kms_key:
    alias: my-kms-key
    policy:
      Version: "2012-10-17"
      Id: auto-ebs-2
      Statement:
        - Action:
            - "kms:*"
          Effect: Allow
          Principal:
            AWS: "*"
          Resource: "*"
          Sid: Allow access through EBS for all principals
    state: present

The policy broadly permits principals and actions without account or service conditions. Review other effective controls as well.

After

yaml
- name: Update IAM policy on an existing KMS key
  amazon.aws.kms_key:
    alias: my-kms-key
    policy: |
      {
        "Id": "auto-ebs-2",
        "Statement": [
          {
            "Sid": "EnableIAMUserPermissions",
            "Effect": "Allow",
            "Principal": {"AWS": "arn:aws:iam::{{ key_account_id }}:root"},
            "Action": "kms:*",
            "Resource": "*"
          },
          {
            "Action": [
              "kms:Encrypt",
              "kms:Decrypt",
              "kms:ReEncrypt*",
              "kms:GenerateDataKey*",
              "kms:CreateGrant",
              "kms:DescribeKey"
            ],
            "Condition": {
              "StringEquals": {
                "kms:CallerAccount": "{{ key_account_id }}",
                "kms:ViaService": "ec2.{{ aws_region }}.amazonaws.com"
              }
            },
            "Effect": "Allow",
            "Principal": {
              "AWS": "*"
            },
            "Resource": "*",
            "Sid": "Allow controlled access through EBS"
          }
        ],
        "Version": "2012-10-17"
      }
    state: present

The first statement preserves delegation through the owning account's IAM policies. The second restricts use to EC2/EBS requests for the specified account. Review required use and administrative permissions alongside the other statements in the existing policy.

References