Description
Unnecessary KMS use or administration permissions can affect data and services that depend on the key. Review the key policy, IAM permissions and KMS grants together. In a key policy, Resource: "*" means the attached key; default account delegation or omitting the policy does not itself imply public access.
Potential impact
Unnecessarily permitted signing, decryption or administration can affect data integrity or service availability. Available operations depend on the key’s purpose and effective permissions.
Remediation
- Separate key users from administrators and restrict permissions to required actions and valid conditions.
- Preserve an administrative path for future
kms:PutKeyPolicycalls and do not bypass the lockout safety check. Verify required use and management operations still work and unwanted requests are denied.
Examples
These examples use an RSA signing/verification key, not a decryption key. Supply the actual signing-role ARN through SigningRoleArn. The owner-account statement in the after-example retains IAM delegation, so deployment and management identities also need appropriate IAM permissions.
Before
Resources:
RSASigningKey:
Type: AWS::KMS::Key
Properties:
Description: RSA-3072 asymmetric CMK for signing and verification
KeySpec: RSA_3072
KeyUsage: SIGN_VERIFY
KeyPolicy:
Version: "2012-10-17"
Id: key-default-1
Statement:
- Sid: Enable IAM User Permissions
Effect: Allow
Principal:
AWS: "*"
Action: kms:*
Resource: "*"
Principals and KMS actions are broadly allowed. Review effective controls and the permissions actually needed.
After
Parameters:
SigningRoleArn:
Type: String
Resources:
RSASigningKey:
Type: AWS::KMS::Key
Properties:
Description: RSA-3072 asymmetric CMK for signing and verification
KeySpec: RSA_3072
KeyUsage: SIGN_VERIFY
KeyPolicy:
Version: "2012-10-17"
Id: key-default-1
Statement:
- Sid: EnableIAMUserPermissions
Effect: Allow
Principal:
AWS: !Sub 'arn:${AWS::Partition}:iam::${AWS::AccountId}:root'
Action: kms:*
Resource: "*"
- Sid: Allow use of the key
Effect: Allow
Principal:
AWS: !Ref SigningRoleArn
Action:
- kms:Sign
- kms:Verify
- kms:DescribeKey
Resource: "*"
Owner-account delegation is retained, and the selected role receives signing, verification and key-description permissions. Review actual access across other policies and grants too.