751 questions
1
vote
0
answers
31
views
Trouble decrypting CiphertextForRecipient after KMS GenerateDataKey
I'm building a route for my go (gin) server that generates a Data Encryption Key (DEK), following the principle of zero-trust (the backend never sees the plaintext).
Right now, the client generates a ...
0
votes
0
answers
57
views
How to setup AWS KMS with pulumi for log group?
I'm having hard time getting my KMS key working for my log group.
Right now I got this error in pulumi up:
policy: operation error KMS: PutKeyPolicy, [some other informations] ...
-4
votes
1
answer
78
views
What is the difference between a key managed by SQS vs a KMS key managed by SQS?
I'm looking into encrypting an SQS Queue that I've got using the CDK, and as options, there are
Encryption type
Description
UNENCRYPTED
Messages in the queue are not encrypted.
KMS_MANAGED
Server-side ...
0
votes
0
answers
29
views
Issues while creating an asymmetric customer managed key for key agreement
I want to create an asymmetric customer managed key for key agreement in Terraform.
The Terraform doc does not specify "KEY_AGREEMENT" as a valid value for key usage, although its provided ...
1
vote
1
answer
102
views
AWS Lambda: Unable to decrypt RDS Activity Stream using KMS (InvalidCiphertextException)
I have a CloudFormation template which I am using to configure lambda to decrypt AWS RDS database activity stream logs
I used the lambda function from: https://github.com/aws-samples/optimising-aws-...
0
votes
0
answers
24
views
AWS KMS Custom Key Store cannot connect to CloudHSM
I'm trying to set up an AWS KMS Custom Key Store using a CloudHSM cluster in eu-north-1, but I'm running into a silent failure: the key store remains in the DISCONNECTED state, and no ...
0
votes
0
answers
61
views
How to make codebuild role in aws account make changes/access KMS keys in another aws account for a lambda function?
How to make codebuild role in aws account make changes/access KMS keys in another aws account for a lambda function?
We are facing below error message when we update lambda function in one aws account ...
0
votes
1
answer
179
views
AWS Athena S3 Access Failing Due to KMS Key Not Found in Cross-Account Setup [closed]
I'm trying to configure AWS Athena in the account A to query a dataset in account B. I updated the S3 bucket policy in account A to enforce secure transport and allow access from a specific IAM ...
0
votes
0
answers
57
views
Error while Copying from S3 to EC2 in different accounts
I am trying to copy some files from S3 in one account to EC2 instance in another account. Bucket and ec2 are in different accounts but same region
I have the appropriate IAM roles attached to the EC2 ...
0
votes
0
answers
49
views
Hoe to add proxy to @aws-crypto/client-node
We are running our containers in an environment that requires a proxy to communicate with AWS services. I was able to set the proxy using AWS.config.update({ httpOptions: { agent } }), but it does not ...
0
votes
0
answers
35
views
AWS service control policy be used to enforce encryption key for secret values
For AWS secrets manager resource we want to ensure encryptions keys are created using certain module our firm has implemented. This module ultimately provisions KMS key in AWS account but requirement ...
0
votes
0
answers
250
views
No Configured Keyring was able to decrypt the Data Key. The list of encountered Exceptions is available via `list`
I am getting an error when I try to decrypt the data which is encrypted by AWS KMS.
Able to encrypt the data without any issue but while decrypting getting the error.
Error: No Configured Keyring was ...
0
votes
1
answer
308
views
Does the IAM policy need include access to the CMK chosen for DynamoDB encryption in order to access the DynamoDB?
When I create a DynamoDB table, I can choose to encrypt the table use a customer managed Key (CMK). My question is when creating an IAM role/policy to allow say, read/write to the table, like dynamodb:...
1
vote
1
answer
128
views
Provide a custom URL to decrypt with KMS
I'm using KMS to encrypt / decrypt data using @aws-crypto/client-node.
I would like to use be able to provide the URL of a custom server to contact for testing purpose. But can't find how to provide ...
0
votes
1
answer
210
views
KMS with encryption SDK - how to do envelope encryption?
I am currently using the aws encryption sdk to encrypt and decrypt some of my data (encrypted at rest).
However, when trying to decrypt a lot of the data at once, it is very slow. On inspection, it ...