How AWS services use AWS KMS

This page was generated from content adapted from the AWS Developer Guide

AWS CloudTrail

  • Important AWS CloudTrail and Amazon S3 support only symmetric AWS KMS keys. You cannot use an asymmetric KMS key to encrypt your CloudTrail Logs. For help determining whether a KMS key is symmetric or asymmetric, see Identifying asymmetric KMS keys.

  • Note You might need to scroll to the right to see some of the callouts in the following example log entry.

  • Note You might need to scroll to the right to see some of the callouts in the following example log entry.

  • Note You might need to scroll to the right to see some of the callouts in the following example log entry.

Amazon Elastic Block Store (Amazon EBS)

Amazon Elastic Transcoder

  • Important For both client-side and server-side encryption, Elastic Transcoder supports only symmetric KMS keys. You cannot use an asymmetric KMS key to encrypt your Elastic Transcoder files. For help determining whether a KMS key is symmetric or asymmetric, see Identifying asymmetric KMS keys.

  • Important AWS never stores your private encryption keys. Therefore, it is important that you manage your keys safely and securely. If you lose them, you won't be able to decrypt your data.

Amazon EMR

Amazon Redshift

  • Important Amazon Redshift supports only symmetric encryption KMS keys. You cannot use an asymmetric KMS key in an Amazon Redshift encryption workflow. For help determining whether a KMS key is symmetric or asymmetric, see Identifying asymmetric KMS keys.

Amazon Relational Database Service (Amazon RDS)

Amazon Simple Email Service (Amazon SES)

AWS Systems Manager Parameter Store

Amazon WorkMail

  • Important Amazon WorkMail supports only symmetric encryption KMS keys. You cannot use an asymmetric KMS key to encrypt data in Amazon WorkMail. For help determining whether a KMS key is symmetric or asymmetric, see Identifying asymmetric KMS keys.

  • Note Amazon WorkMail uses a symmetric mailbox encryption key to protect message keys. Previously, Amazon WorkMail protected each mailbox with an asymmetric key pair. It used the public key to encrypt each message key and the private key to decrypt it. The private mailbox key was protected by the KMS key for the organization. Existing mailboxes might still use an asymmetric mailbox key pair. This change does not affect the security of the mailbox or its messages.

WorkSpaces

  • Important WorkSpaces supports only symmetric encryption KMS keys. You cannot use an asymmetric KMS key to encrypt the volumes in an WorkSpaces. For help determining whether a KMS key is symmetric or asymmetric, see Identifying asymmetric KMS keys.

Last updated