All Content tagged with AWS Key Management Service
AWS Key Management Service (KMS) makes it easy for you to create and manage cryptographic keys and control their use across a wide range of AWS services and in your applications.
Content language: English
Filter content
Select tags to filter
Sort by
Sort by most recent
442 results
WAZEXPERT
published 15 days ago0 votes107 views
Part 3 of a three-part series mapping the OWASP Top 10 for Agentic Applications 2026 to AWS security controls. This final part covers the system's dynamics once agents persist state and act autonomous...
I opted into UAE (me-central-1) on a new-ish account and can't launch compute there.
- ecs:CreateCluster → ThrottlingException: "Rate exceeded" (every call, 24h+, even single calls after long idle).
...
2
answers
-2
votes
77
views
asked 25 days ago
Abhishek Avinash AgawaneSUPPORT ENGINEER
published 2 months ago0 votes183 views
Many production Amazon RDS and Aurora databases still use self-managed master passwords stored in templates, variables, or pipeline secrets, creating exposure and rotation risks. This article is a com...
RodrigoSUPPORT ENGINEER
published 2 months ago3 votes213 views
An open source command line interface (CLI) that uses CloudTrail and Athena to quantify your S3 bucket key efficiency.
In [Amazon EC2 instance attestation documentation](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/nitrotpm-attestation.html) there are instructions how to build an AMI, get PCR values for the ima...
1
answers
0
votes
60
views
Jason ShenSUPPORT ENGINEER
published 3 months ago0 votes193 views
After Amazon GuardDuty Malware Protection for S3 scans an uploaded object, you might want to automatically move clean files to a trusted bucket and quarantine infected files. This article shows how to...
Dennis_OEXPERT
published 3 months ago2 votes258 views
For sensitive caller inputs (PAN, CVV, authentication codes), post-call redaction is not enough PCI DSS v4.0 requires CVV is never stored after authorization and PAN only stored encrypted. This articl...
Dennis_OEXPERT
published 3 months ago1 votes169 views
Connect encrypts customer content at rest by default with a service-managed KMS key, but customers in regulated industries (PCI DSS v4.0, GDPR, HIPAA) typically need full key control — independent rot...
I'm trying to import an external AES-256 KEK into AWS Payment Cryptography
using DiffieHellmanTr31KeyBlock in ap-southeast-1. Every attempt returns:
ValidationException: KeyBlock data in the importe...
1
answers
1
votes
71
views
asked 3 months ago
Naveen JagathesanEXPERT
published 3 months ago0 votes190 views
Running Spark on EMR with KMS-encrypted S3 data? Every object read triggers a kms:Decrypt API call — and at scale, those costs add up fast. If your compliance requirements prevent switching to S3 Buck...

AWS OFFICIALUpdated 4 months ago0 votes362 views
This article shows you how to create a fallback mechanism to add resiliency to authentication in the AWS Management Console.
I would like to use AWS KMS for code signing. Additionally, I would like to publish transparency logs as an assurance that the signing key has not signed unknown code. However CloudTrail logs don't in...
1
answers
-1
votes
99
views
asked 4 months ago