Skip to content

Questions tagged with AWS Key Management Service

AWS Key Management Service (KMS) makes it easy for you to create and manage cryptographic keys and control their use across a wide range of AWS services and in your applications.

Content language: English

Filter questions
Select tags to filter
Sort by
Sort by most recent
Filter Questions by:

Browse through the questions and answers listed below or filter and sort to narrow down your results.

407 results
I gate a KMS key on Nitro Enclave attestation so that only my enclave can decrypt a particular piece of material. ## The trade-off as I understand it Binding the key policy to `kms:RecipientAttestat...
1
answers
0
votes
60
views

asked 9 days ago

I'm building a signing service inside an AWS Nitro Enclave and I need a way to detect rollback of state that the enclave itself authored but cannot store. ## Setup The enclave has no persistent stor...
1
answers
0
votes
36
views

asked 9 days ago

Creation of two `AWS::BedrockAgentCore::Gateway` resources fails during AgentCore’s internal Policy Engine validation. AgentCore successfully assumes each customer-supplied Gateway execution role...
4
answers
0
votes
72
views

asked 23 days ago

I opted into UAE (me-central-1) on a new-ish account and can't launch compute there. - ecs:CreateCluster → ThrottlingException: "Rate exceeded" (every call, 24h+, even single calls after long idle). ...
2
answers
-2
votes
91
views

asked 2 months ago

In [Amazon EC2 instance attestation documentation](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/nitrotpm-attestation.html) there are instructions how to build an AMI, get PCR values for the ima...
1
answers
0
votes
65
views
EXPERT

asked 4 months ago

I'm trying to import an external AES-256 KEK into AWS Payment Cryptography using DiffieHellmanTr31KeyBlock in ap-southeast-1. Every attempt returns: ValidationException: KeyBlock data in the importe...
1
answers
1
votes
125
views

asked 4 months ago

I would like to use AWS KMS for code signing. Additionally, I would like to publish transparency logs as an assurance that the signing key has not signed unknown code. However CloudTrail logs don't in...
1
answers
-1
votes
109
views

asked 5 months ago

We store our passwords for our endpoints in secrets manager. These rotate every 7 days. We are noticing when the password rotates, the CDC then fails. Is there a way to keep DMS updated with secrets ...
3
answers
0
votes
147
views

asked 5 months ago

![Error Message](/media/postImages/original/IMYD-uXZk1Qyikhujequ0QEA) I’m trying to validate a cross-organization backup copy scenario and would appreciate clarification. **Scenario** * Account A1 in...
1
answers
0
votes
196
views

asked 7 months ago

Hi everyone, I’m designing a system in AWS where I need to manage around 10,000 users, each with a crypto wallet key pair (public + private key) that must be stored securely. What would be the best ...
2
answers
0
votes
170
views

asked 7 months ago

I have an existing Amazon MSK cluster that was created using the AWS managed KMS key for encryption at rest. I now have a requirement to use a customer-managed KMS key (CMK) instead. Questions: Ca...
1
answers
0
votes
146
views

asked 7 months ago

I have an existing Amazon MSK cluster that was created using the AWS managed KMS key (aws/kafka) for encryption at rest. I now have a requirement to use a customer-managed KMS key (CMK) instead. I re...
1
answers
0
votes
139
views

asked 7 months ago

  • 1
  • 2
  • 3
  • 4
  • 5
  • •••
  • 34
  • Page size
    12 / page