Can't cleanup obsolete Customer managed keys in Key Management Service

0

No being able to view details, disable and/or schedule key deletion. Getting:

DescribeKey request failed AccessDeniedException - User: arn:aws:iam:::user/root is not authorized to perform: kms:DescribeKey on resource: arn:aws:kms:us-east-1::key/005aa284-c9a3-4b75-8eaa-de1ac998786d because no resource-based policy allows the kms:DescribeKey action

DisableKey request failed AccessDeniedException - User: arn:aws:iam:::user/root is not authorized to perform: kms:DisableKey on resource: arn:aws:kms:us-east-1::key/005aa284-c9a3-4b75-8eaa-de1ac998786d because no resource-based policy allows the kms:DisableKey action

AWS Support under "Account and billing" saying: This issue is beyond our scope on the Billing and Accounts team ... For additional technical help, you can engage our support engineers by posting to AWS re:Post ... You can also contact Premium (!?) Support.

Appreciate your advice.

Artem
質問済み 3ヶ月前94ビュー
1回答
0

Hi, Artem

Please check this AWS document https://docs.aws.amazon.com/kms/latest/developerguide/key-policy-default.html for KMS resource-based policy.

If this helps solve your problem, please choose this as the Accepted Answer so others on re:Post may benefit - Thank you!

profile pictureAWS
回答済み 3ヶ月前
profile picture
エキスパート
レビュー済み 1ヶ月前

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

質問に答えるためのガイドライン

関連するコンテンツ