Description
A KMS key policy that grants unnecessary principals decryption or key-management permissions can affect data protection and key availability. Separate key-use operations from administration and review the actual key policy, IAM permissions and KMS grants together.
In a key policy, Resource: "*" means the key to which the policy is attached, not every key. Creating a key through the API without a policy applies a default that enables the owning account to delegate access through IAM policies. Do not remove this account delegation or necessary administration solely because it uses a wildcard.
Potential impact
- Unnecessary effective decryption or management permissions can broaden data access or disrupt services that depend on the key.
- Removing essential administrative access can prevent future policy changes. Adding a nominal condition does not necessarily restrict access.
Remediation
- Identify the actual policy and required users, roles and services. Minimize key-use and administrative permissions separately. In
amazon.aws11.4.0, omitting the policy when managing an existing key preserves its current policy. - Restrict principals and actions with effective conditions.
kms:CallerAccountlimits the account initiating the request;kms:ViaServicelimits supported AWS services making requests on a principal's behalf. Test allowed and denied requests using the actual account, Region and service path. - Preserve a path for future
kms:PutKeyPolicycalls and do not bypass the lockout safety check. Verify key administration, recovery and required service access after the change.
Examples
Replace my-kms-key with the actual alias. In the after-example, key_account_id is the key-owning account and aws_region is the Region where EC2/EBS uses the key. Preserve required statements from the existing policy, and confirm that the deployment identity retains policy-management access through IAM permissions before applying it.
Before
- name: Update IAM policy on an existing KMS key
amazon.aws.kms_key:
alias: my-kms-key
policy:
Version: "2012-10-17"
Id: auto-ebs-2
Statement:
- Action:
- "kms:*"
Effect: Allow
Principal:
AWS: "*"
Resource: "*"
Sid: Allow access through EBS for all principals
state: present
The policy broadly permits principals and actions without account or service conditions. Review other effective controls as well.
After
- name: Update IAM policy on an existing KMS key
amazon.aws.kms_key:
alias: my-kms-key
policy: |
{
"Id": "auto-ebs-2",
"Statement": [
{
"Sid": "EnableIAMUserPermissions",
"Effect": "Allow",
"Principal": {"AWS": "arn:aws:iam::{{ key_account_id }}:root"},
"Action": "kms:*",
"Resource": "*"
},
{
"Action": [
"kms:Encrypt",
"kms:Decrypt",
"kms:ReEncrypt*",
"kms:GenerateDataKey*",
"kms:CreateGrant",
"kms:DescribeKey"
],
"Condition": {
"StringEquals": {
"kms:CallerAccount": "{{ key_account_id }}",
"kms:ViaService": "ec2.{{ aws_region }}.amazonaws.com"
}
},
"Effect": "Allow",
"Principal": {
"AWS": "*"
},
"Resource": "*",
"Sid": "Allow controlled access through EBS"
}
],
"Version": "2012-10-17"
}
state: present
The first statement preserves delegation through the owning account's IAM policies. The second restricts use to EC2/EBS requests for the specified account. Review required use and administrative permissions alongside the other statements in the existing policy.