説明
AWS IoT ポリシーで Action: "*" を許可すると、ポリシーのリソース範囲内で対応する操作を広く許可します。
想定される影響
デバイスが不要な操作権限を持つと、誤動作や認証情報の侵害による影響が大きくなるおそれがあります。
対処方法
接続、発行、購読など、必要な操作だけを指定し、各操作に適切なリソース範囲を設定してください。
例
この例は特定クライアントの iot:Connect 権限を明示しています。操作とリソースの両方で権限範囲が決まるため、実際のクライアント ID に合わせて設定してください。
変更前
yaml
AWSTemplateFormatVersion: 2010-09-09
Description: A sample template
Resources:
IoTPolicy:
Type: AWS::IoT::Policy
Properties:
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action: "*"
Resource:
- arn:aws:iot:us-east-1:123456789012:client/client
PolicyName: PolicyName
変更後
yaml
AWSTemplateFormatVersion: 2010-09-09
Description: A sample template
Resources:
IoTPolicy:
Type: AWS::IoT::Policy
Properties:
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- iot:Connect
Resource:
- arn:aws:iot:us-east-1:123456789012:client/client1
PolicyName: PolicyName