KMS key policy permissions need review

Limit KMS use and administration permissions while preserving a path to manage the key policy.

Description

Unnecessary KMS use or administration permissions can affect data and services that depend on the key. Review the key policy, IAM permissions and KMS grants together. In a key policy, Resource: "*" means the attached key; default account delegation or omitting the policy does not itself imply public access.

Potential impact

Unnecessarily permitted signing, decryption or administration can affect data integrity or service availability. Available operations depend on the key’s purpose and effective permissions.

Remediation

  • Separate key users from administrators and restrict permissions to required actions and valid conditions.
  • Preserve an administrative path for future kms:PutKeyPolicy calls and do not bypass the lockout safety check. Verify required use and management operations still work and unwanted requests are denied.

Examples

These examples use an RSA signing/verification key, not a decryption key. Supply the actual signing-role ARN through SigningRoleArn. The owner-account statement in the after-example retains IAM delegation, so deployment and management identities also need appropriate IAM permissions.

Before

yaml
Resources:
  RSASigningKey:
    Type: AWS::KMS::Key
    Properties:
      Description: RSA-3072 asymmetric CMK for signing and verification
      KeySpec: RSA_3072
      KeyUsage: SIGN_VERIFY
      KeyPolicy:
        Version: "2012-10-17"
        Id: key-default-1
        Statement:
          - Sid: Enable IAM User Permissions
            Effect: Allow
            Principal:
              AWS: "*"
            Action: kms:*
            Resource: "*"

Principals and KMS actions are broadly allowed. Review effective controls and the permissions actually needed.

After

yaml
Parameters:
  SigningRoleArn:
    Type: String
Resources:
  RSASigningKey:
    Type: AWS::KMS::Key
    Properties:
      Description: RSA-3072 asymmetric CMK for signing and verification
      KeySpec: RSA_3072
      KeyUsage: SIGN_VERIFY
      KeyPolicy:
        Version: "2012-10-17"
        Id: key-default-1
        Statement:
          - Sid: EnableIAMUserPermissions
            Effect: Allow
            Principal:
              AWS: !Sub 'arn:${AWS::Partition}:iam::${AWS::AccountId}:root'
            Action: kms:*
            Resource: "*"
          - Sid: Allow use of the key
            Effect: Allow
            Principal:
              AWS: !Ref SigningRoleArn
            Action:
              - kms:Sign
              - kms:Verify
              - kms:DescribeKey
            Resource: "*"

Owner-account delegation is retained, and the selected role receives signing, verification and key-description permissions. Review actual access across other policies and grants too.

References