Description
A KMS key policy that allows more principals or operations than necessary can grant excessive decryption or key-management permissions. Separate key use from administration and review effective access together with IAM policies and grants.
If no key policy is supplied, AWS applies a default policy enabling the account to delegate access through IAM. This differs from granting public access to every principal. In a key policy, Resource: "*" means the key to which the policy is attached.
Potential impact
- Unnecessary decryption permissions can expose data protected by the key.
- Excessive policy-change or key-disable permissions, or accidentally removing administration access, can interrupt data access and recovery.
Remediation
- Limit key users to required identities and cryptographic operations, controlling administration through a separate trusted path.
- Review conditions suited to the actual service and consider key policies, IAM policies and grants together.
- Before policy changes, preserve management permissions for administrators and deployment identities, then test required encryption and decryption and rejection of unwanted access.
Examples
These excerpts compare key policies. Replace the example account ID and user ARN with actual approved values. The account IAM-delegation statement preserves an administration path; IAM policies using it must also follow least privilege.
Before
resource "aws_kms_key" "kms_key" {
description = "KMS key 1"
deletion_window_in_days = 10
policy = <<POLICY
{
"Version": "2012-10-17",
"Statement":[
{
"Effect":"Allow",
"Principal": {"AWS":"*"},
"Action":["kms:*"],
"Resource":"*"
}
]
}
POLICY
}
This allows kms:* to a wildcard principal. Remove or narrow such broad permissions while considering other controls applicable to actual requests.
After
resource "aws_kms_key" "kms_key" {
description = "KMS key 1"
deletion_window_in_days = 10
policy = <<POLICY
{
"Version": "2012-10-17",
"Statement":[
{
"Sid": "EnableAccountIAMPermissions",
"Effect": "Allow",
"Principal": {"AWS": "arn:aws:iam::111122223333:root"},
"Action": "kms:*",
"Resource": "*"
},
{
"Effect":"Allow",
"Principal": {"AWS": [
"arn:aws:iam::111122223333:user/CMKUser"
]},
"Action": [
"kms:Encrypt",
"kms:Decrypt",
"kms:ReEncrypt*",
"kms:GenerateDataKey*",
"kms:DescribeKey"
],
"Resource":"*"
}
]
}
POLICY
}
This preserves account IAM delegation and allows the listed key-use operations for the named user. Reduce the listed operations further to actual needs.