Unable to connect to EC2 using SSM.ap-southeast-1.amazonaws.com

0

Dear all Gurus,

I am facing some issue on EC2 connect. When I am using the viaservice condition ssm.ap-southeast-1.awazonaws.com It prompt me that I do not have permission. When I remove this condition, i can access the EC2 without any issues.

any idea that I can use other service name to limit the condition?

Thank you in advance.

McDs23
feita há um ano269 visualizações
2 Respostas
0

What IAM policies are you actually using?

Also, are you using Systems Manager Session Manager to connect to EC2?

profile picture
ESPECIALISTA
respondido há um ano
  • IAM currently is full access administator. cause I am doing some testing. Yes I am using System Managers Session Manager to Connect to EC2. Currently, I need to encrypt the ssm session with kms key with viaservice or condition limited. May I know which via services or condition that I can put in for testing? TYIA

  • Can you please share the IAM policy you have set up for EC2 and the full text of the connection error?

    Is the EC2 running on a private subnet? If so, are KMS VPC endpoints and NAT gateways configured?

0

IAM is full administrator rights. when i added this condition "kms:ViaService": "ssm.ap-southeast-1.amazonaws.com"

I cannot (connect) button in Connect to Instance (Session Manager), the error said that I do not have the kms:GenerateDataKey in key policy which it is in place. Once I remove this permission "kms:ViaService": "ssm.ap-southeast-1.amazonaws.com" I am able to connect to the EC2.

I am trying to limit the key usages by using the condition of via service.

McDs23
respondido há um ano

Você não está conectado. Fazer login para postar uma resposta.

Uma boa resposta responde claramente à pergunta, dá feedback construtivo e incentiva o crescimento profissional de quem perguntou.

Diretrizes para responder a perguntas