Review principals allowed by a KMS key policy

Limit who can administer or use a KMS key to the required scope.

Description

Allowing Principal: "*" in a KMS key policy without suitable limiting conditions can make the set of principals able to access the key too broad.

Potential impact

Depending on the allowed actions, unintended principals may be able to use the key or change its management settings.

Remediation

Specify required principals and conditions, and separate key administration from key use. Ensure required administrative access remains available after changing the policy.

Examples

The after-example enables delegation through IAM policies in a specific account. A root ARN does not restrict access to the root user alone. Resource: "*" in a key policy refers to this key.

Before

yaml
AWSTemplateFormatVersion: 2010-09-09
Description: A sample template
Resources:
  myKey:
    Type: AWS::KMS::Key
    Properties:
      Description: An example symmetric CMK
      KeyPolicy:
        Version: "2012-10-17"
        Id: key-default-1
        Statement:
          - Sid: Enable IAM User Permissions
            Effect: Allow
            Principal: "*"
            Action: kms:*
            Resource: "*"

After

yaml
AWSTemplateFormatVersion: 2010-09-09
Description: A sample template
Resources:
  myKey:
    Type: AWS::KMS::Key
    Properties:
      Description: An example symmetric CMK
      KeyPolicy:
        Version: "2012-10-17"
        Id: key-default-1
        Statement:
          - Sid: Enable IAM User Permissions
            Effect: Allow
            Principal:
              AWS: arn:aws:iam::111122223333:root
            Action: kms:*
            Resource: "*"

References