KMS, Envelope Encryption & Private CA
AWS for Interviews: lesson 14 of 18
Wrap a data key with a KMS key; let a private CA sign what you trust.
Lesson 14 of 18 · 7 min
KMS, Envelope Encryption & Private CA
Step 1 of 10
Encrypt a 2 GB backup with KMS. A KMS key never leaves KMS unencrypted — and the 2 GB file is not sent to KMS either.
The Idea
Every KMS key has exactly one key policy; IAM policies grant access only if that policy allows them. KMS keys never leave KMS unencrypted, so large data uses envelope encryption: GenerateDataKey returns a data key in plaintext and encrypted. Encrypt locally, erase the plaintext, store the encrypted key with the data. Multi-Region keys share key ID and material across Regions. AWS Private CA runs root and subordinate CAs that issue private certificates.
Real-World Example
A backup job encrypts each file under its own data key. The replica of its multi-Region key decrypts restores in the recovery Region. Internal services get TLS certificates from a subordinate CA; the root CA signs only subordinates.
The Tradeoff
Key policies are Regional, so each replica key's policy is yours to keep in step. A compromised root CA breaks trust in everything below it, which is why it stays locked away.
Hands-On
# illustrative — key ID and Region are placeholders
aws kms generate-data-key --key-id alias/backup --key-spec AES_256
# returns Plaintext (use it, then erase it) and CiphertextBlob (store it)
aws kms decrypt --ciphertext-blob fileb://key.enc \
--query Plaintext --output text
aws kms replicate-key --key-id mrk-1234abcd \
--replica-region eu-west-1
Your turn
Put the steps in the right order.
- Encrypt the file locally with the plaintext data key
- Call GenerateDataKey with the KMS key
- To read it later, send the encrypted data key to KMS Decrypt
- Erase the plaintext key and store the encrypted data key with the file
Mini quiz
1 / 3
A role's IAM policy allows kms:Decrypt on a key, but the key policy neither names the role nor enables IAM policies. The call:
Sources
- Key policies in AWS KMS — AWS Key Management Service Developer Guide
- AWS KMS cryptography essentials — AWS Key Management Service Developer Guide
- GenerateDataKey — AWS Key Management Service API Reference
- Multi-Region keys in AWS KMS — AWS Key Management Service Developer Guide
- Design a CA hierarchy — AWS Private CA User Guide