Description
Allowing Resource: "*" in an AWS IoT policy broadens the targets of the specified actions. For example, iot:Connect can allow connections using unintended client IDs.
Potential impact
Device isolation can be weakened, or connections using the same client ID can conflict.
Remediation
Specify client, topic or topic filter ARNs appropriate to each action. Define the permitted device IDs and paths, then verify connection and messaging permissions.
Examples
The examples restrict connection permission to client1. Use the resource ARN required by each other IoT action.
Before
yaml
AWSTemplateFormatVersion: 2010-09-09
Description: A sample template
Resources:
IoTPolicy:
Type: AWS::IoT::Policy
Properties:
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- iot:Connect
Resource: "*"
PolicyName: PolicyName
After
yaml
AWSTemplateFormatVersion: 2010-09-09
Description: A sample template
Resources:
IoTPolicy:
Type: AWS::IoT::Policy
Properties:
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- iot:Connect
Resource:
- arn:aws:iot:us-east-1:123456789012:client/client1
PolicyName: PolicyName