Unable to connect to EC2 using SSM.ap-southeast-1.amazonaws.com

0

Dear all Gurus,

I am facing some issue on EC2 connect. When I am using the viaservice condition ssm.ap-southeast-1.awazonaws.com It prompt me that I do not have permission. When I remove this condition, i can access the EC2 without any issues.

any idea that I can use other service name to limit the condition?

Thank you in advance.

McDs23
preguntada hace un año268 visualizaciones
2 Respuestas
0

What IAM policies are you actually using?

Also, are you using Systems Manager Session Manager to connect to EC2?

profile picture
EXPERTO
respondido hace un año
  • IAM currently is full access administator. cause I am doing some testing. Yes I am using System Managers Session Manager to Connect to EC2. Currently, I need to encrypt the ssm session with kms key with viaservice or condition limited. May I know which via services or condition that I can put in for testing? TYIA

  • Can you please share the IAM policy you have set up for EC2 and the full text of the connection error?

    Is the EC2 running on a private subnet? If so, are KMS VPC endpoints and NAT gateways configured?

0

IAM is full administrator rights. when i added this condition "kms:ViaService": "ssm.ap-southeast-1.amazonaws.com"

I cannot (connect) button in Connect to Instance (Session Manager), the error said that I do not have the kms:GenerateDataKey in key policy which it is in place. Once I remove this permission "kms:ViaService": "ssm.ap-southeast-1.amazonaws.com" I am able to connect to the EC2.

I am trying to limit the key usages by using the condition of via service.

McDs23
respondido hace un año

No has iniciado sesión. Iniciar sesión para publicar una respuesta.

Una buena respuesta responde claramente a la pregunta, proporciona comentarios constructivos y fomenta el crecimiento profesional en la persona que hace la pregunta.

Pautas para responder preguntas