How can an AWS KMS customer master key (CMK) be constrained to work with only Amazon S3?

2 Comments

  1. Dylan
    Author

    To the best of my knowledge, the answer is:
    Configure the CMK key policy to allow AWS KMS actions only when the kms:ViaService condition matches the Amazon S3 service name.

  2. Alexander
    Author

    As far as I’m aware, the answer is:
    Configure the CMK key policy to allow AWS KMS actions only when the kms:ViaService condition matches the Amazon S3 service name.

Leave a Reply to Alexander Cancel reply

Your email address will not be published. Required fields are marked *

one + 2 =