Description
A disabled KMS key or a key actually pending deletion can cause cryptographic operations that require it to fail. Encryption at rest does not prevent a service outage when its key is unavailable.
PendingWindowInDays sets the waiting period when CloudFormation deletes the key. Setting this property does not itself schedule deletion or disable the key. Check the actual key state and dependent services.
Potential impact
- Data reads, resource creation or backup recovery that require the key can fail.
- Once the key is deleted, data that can only be decrypted with it may be unrecoverable.
Remediation
- Check key state and permissions, investigate why a key was disabled, and enable it when it is still needed.
- If deletion is scheduled for a required key, cancel deletion in KMS and enable the key again. Adding a key back to the template does not restore the original key.
- Before retiring a key, verify that existing data and backups no longer depend on it for decryption.
Examples
These examples compare key availability. Configure application permissions to use the key separately.
Before
Resources:
AppKey:
Type: AWS::KMS::Key
Properties:
Enabled: false
PendingWindowInDays: 7
KeyPolicy:
Version: '2012-10-17'
Statement:
- Effect: Allow
Principal:
AWS: !Sub arn:aws:iam::${AWS::AccountId}:root
Action: kms:*
Resource: "*"
Enabled: false prevents cryptographic use of the key. PendingWindowInDays: 7 specifies a waiting period for deletion; it does not establish that deletion is currently pending.
After
Resources:
AppKey:
Type: AWS::KMS::Key
Properties:
Enabled: true
KeyPolicy:
Version: '2012-10-17'
Statement:
- Effect: Allow
Principal:
AWS: !Sub arn:aws:iam::${AWS::AccountId}:root
Action: kms:*
Resource: "*"
The key is enabled. Omitting the waiting period does not prevent deletion, so manage the actual key state and deletion permissions.