Thursday, August 4, 2022
HomeCyber SecurityUseful resource handler returned message: “The brand new key coverage won't assist...

Useful resource handler returned message: “The brand new key coverage won’t assist you to replace the important thing coverage sooner or later. (Service: Kms, Standing Code: 400)” (HandlerErrorCode: InvalidRequest) | by Teri Radichel | Bugs That Chunk | Aug, 2022


BUG with this error message

I feel this error message is a bug in CloudFormation. The explanation I say that’s as a result of I crated a KMS coverage with all KMS privileges for all KMS sources for my present person that’s deploying the KMS key and I get an error stating that the important thing coverage won’t assist you to replace it sooner or later.

In case this error message was associated to not giving the basis person permissions, I added permissions for that person as nicely and that didn’t resolve the issue. I gave the basis person (directors within the account truly) full permissions to all sources. Positively a bug.

So I searched round and located this weblog submit — which confirms what I might count on. You do NOT want give the basis person full admin entry to your key.

I modified two issues to get this working and I’m unsure which one mounted it however I count on it was the quotes:

  1. I modified the double quotes across the * in my coverage:
'*'

to double quotes:

"*"

2. I modified the Sid to match precisely what’s said within the above weblog submit:

"Sid": "Permit administration of the important thing"

3. I added an ID just like the one within the lob submit:

"Id": "key-default-1"

4. I had single quotes round another values which I merely eliminated.

Nevertheless this logic on this error message is figuring out somebody goes to lock themselves out of enhancing their key coverage has a bug and it took me eternally (in impatient programmer minutes) to resolve this.

Teri Radichel

In case you appreciated this story please clap and comply with:

Medium: Teri Radichel or E mail Checklist: Teri Radichel
Twitter: @teriradichel or @2ndSightLab
Requests companies through LinkedIn: Teri Radichel or IANS Analysis

© 2nd Sight Lab 2022

____________________________________________

Writer:

Cybersecurity for Executives within the Age of Cloud on Amazon

Want Cloud Safety Coaching? 2nd Sight Lab Cloud Safety Coaching

Is your cloud safe? Rent 2nd Sight Lab for a penetration check or safety evaluation.

Have a Cybersecurity or Cloud Safety Query? Ask Teri Radichel by scheduling a name with IANS Analysis.

Cybersecurity & Cloud Safety Assets by Teri Radichel: Cybersecurity and Cloud safety lessons, articles, white papers, shows, and podcasts



RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments