How can an AWS KMS customer master key (CMK) be constrained to work with only Amazon S3?

1 Comment

  1. Dylan
    Author

    To the best of my knowledge, the answer is:
    Configure the CMK key policy to allow AWS KMS actions only when the kms:ViaService condition matches the Amazon S3 service name.

Leave a Reply

Your email address will not be published. Required fields are marked *

three + two =