Description
Allowing Principal: "*" in a KMS key policy without suitable limiting conditions can make the set of principals able to access the key too broad.
Potential impact
Depending on the allowed actions, unintended principals may be able to use the key or change its management settings.
Remediation
Specify required principals and conditions, and separate key administration from key use. Ensure required administrative access remains available after changing the policy.
Examples
The after-example enables delegation through IAM policies in a specific account. A root ARN does not restrict access to the root user alone. Resource: "*" in a key policy refers to this key.
Before
yaml
AWSTemplateFormatVersion: 2010-09-09
Description: A sample template
Resources:
myKey:
Type: AWS::KMS::Key
Properties:
Description: An example symmetric CMK
KeyPolicy:
Version: "2012-10-17"
Id: key-default-1
Statement:
- Sid: Enable IAM User Permissions
Effect: Allow
Principal: "*"
Action: kms:*
Resource: "*"
After
yaml
AWSTemplateFormatVersion: 2010-09-09
Description: A sample template
Resources:
myKey:
Type: AWS::KMS::Key
Properties:
Description: An example symmetric CMK
KeyPolicy:
Version: "2012-10-17"
Id: key-default-1
Statement:
- Sid: Enable IAM User Permissions
Effect: Allow
Principal:
AWS: arn:aws:iam::111122223333:root
Action: kms:*
Resource: "*"