Skip to content
BytePatterns

KMS, Envelope Encryption & Private CA

AWS for Interviews: lesson 14 of 18

Wrap a data key with a KMS key; let a private CA sign what you trust.

Lesson 14 of 18 · 7 min

KMS, Envelope Encryption & Private CA

Step 1 of 10

Encrypt a 2 GB backup with KMS. A KMS key never leaves KMS unencrypted — and the 2 GB file is not sent to KMS either.

The Idea

Every KMS key has exactly one key policy; IAM policies grant access only if that policy allows them. KMS keys never leave KMS unencrypted, so large data uses envelope encryption: GenerateDataKey returns a data key in plaintext and encrypted. Encrypt locally, erase the plaintext, store the encrypted key with the data. Multi-Region keys share key ID and material across Regions. AWS Private CA runs root and subordinate CAs that issue private certificates.

Real-World Example

A backup job encrypts each file under its own data key. The replica of its multi-Region key decrypts restores in the recovery Region. Internal services get TLS certificates from a subordinate CA; the root CA signs only subordinates.

The Tradeoff

Key policies are Regional, so each replica key's policy is yours to keep in step. A compromised root CA breaks trust in everything below it, which is why it stays locked away.

Hands-On

# illustrative — key ID and Region are placeholders
aws kms generate-data-key --key-id alias/backup --key-spec AES_256
# returns Plaintext (use it, then erase it) and CiphertextBlob (store it)
aws kms decrypt --ciphertext-blob fileb://key.enc \
  --query Plaintext --output text
aws kms replicate-key --key-id mrk-1234abcd \
  --replica-region eu-west-1

Your turn

Put the steps in the right order.

  1. Encrypt the file locally with the plaintext data key
  2. Call GenerateDataKey with the KMS key
  3. To read it later, send the encrypted data key to KMS Decrypt
  4. Erase the plaintext key and store the encrypted data key with the file

Mini quiz

1 / 3

A role's IAM policy allows kms:Decrypt on a key, but the key policy neither names the role nor enables IAM policies. The call:

Sources

Keep going

Certification prepPreparing for SCS-C03? Try the free 65-question practice exam

ReferenceBig-O cheat sheetPatterns cheat sheet

New lessons land every few weeks

Leave an address and we will tell you when the next one is up. That is the only reason we will use it.

One address, stored so we can email you. Nothing else, ever.