Help Center> Object Storage Service> FAQs> Server-Side Encryption> Why Cannot an Authorized Account or User Upload or Download KMS Encrypted Objects?
Updated on 2023-10-26 GMT+08:00

Why Cannot an Authorized Account or User Upload or Download KMS Encrypted Objects?

Before using the server-side encryption of OBS, ensure that the OBS OperateAccess and KMS-related permissions have been granted to the account or user on IAM. If the current account or user is the grantee, it also requires the OBS OperateAccess permission. Contact your delegating party for authorization. For details, see Account Delegation.

  • To access OBS, you need to obtain a temporary access key pair and a security token using an agency.
  • DEW is not a global service and KMS is a sub-service of it, so the KMS Administrator permission must be configured for the region where the bucket is located.
  • The agency information is stored on IAM. The configuration takes effect approximately 15 minutes after the configuration is complete.

Server-Side Encryption FAQs

more