Why Cannot an Authorized Account or User Upload or Download KMS Encrypted Objects?
Before using the server-side encryption of OBS, ensure that the OBS OperateAccess and KMS-related permissions have been granted to the account or user on IAM. If the current account or user is the grantee, it also requires the OBS OperateAccess permission. Contact your delegating party for authorization. For details, see Account Delegation.
- To access OBS, you need to obtain a temporary access key pair and a security token using an agency.
- DEW is not a global service and KMS is a sub-service of it, so the KMS Administrator permission must be configured for the region where the bucket is located.
- The agency information is stored on IAM. The configuration takes effect approximately 15 minutes after the configuration is complete.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.