Help Center/ Object Storage Service/ FAQs/ Server-Side Encryption/ Why Cannot an Authorized Account or User Upload or Download KMS Encrypted Objects?
Updated on 2026-01-04 GMT+08:00

Why Cannot an Authorized Account or User Upload or Download KMS Encrypted Objects?

Before using the server-side encryption of OBS, ensure that the OBS OperateAccess and KMS-related permissions have been granted to the account or user on IAM. If the current account or user is the grantee, it also requires the OBS OperateAccess permission. Contact your delegating party for authorization. For details, see Account Delegation.

  • To access OBS, you need to obtain a temporary access key pair and a security token using an agency.
  • Data Encryption Workshop is not a global service, so the KMS Administrator permission in the agency must be configured for the region where the bucket is located.
  • The agency information is stored in IAM. After the configuration is complete, it takes about 15 minutes for the permissions to take effect.