Why Cannot an Authorized Account or User Upload or Download KMS Encrypted Objects?
Before using the server-side encryption of OBS, ensure that the OBS OperateAccess and KMS-related permissions have been granted to the account or user on IAM. If the current account or user is the grantee, it also requires the OBS OperateAccess permission. Contact your delegating party for authorization. For details, see Account Delegation.
- To access OBS, you need to obtain a temporary access key pair and a security token using an agency.
- DEW is not a global service and KMS is a sub-service of it, so the KMS Administrator permission must be configured for the region where the bucket is located.
- The agency information is stored on IAM. The configuration takes effect approximately 15 minutes after the configuration is complete.
Server-Side Encryption FAQs
- Does OBS Support Encrypted Upload?
- How Do I Access or Download an Encrypted Object?
- Why Cannot an Authorized Account or User Upload or Download KMS Encrypted Objects?
- What Encryption Technologies Can I Use to Encrypt Data on OBS?
- Will OBS Server-Side Encryption Encrypt My Existing Objects That Are Unencrypted?
- Will I Be Billed for the Encryption Provided by OBS Server-Side Encryption?
- Does OBS SSE-KMS Allow Anonymous Access?
- Are Additional Permissions Required When I Share an Object with SSE-OBS Encrypted?
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbotmore