CommunityDEENDEENProductsCore ServicesRoadmapRelease NotesService descriptionCertifications and attestationsPrivate CloudManaged ServicesBenefitsSecurity/DSGVOSustainabilityOpenStackMarket leaderPricesPricing modelsComputing & ContainersStorageNetworkDatabase & AnalysisSecurityManagement & ApplicationsPrice calculatorSolutionsIndustriesHealthcarePublic SectorScience and researchAutomotiveMedia and broadcastingRetailUse CasesArtificial intelligenceHigh Performance ComputingBig data and analyticsInternet of ThingsDisaster RecoveryData StorageTurnkey solutionsTelekom cloud solutionsPartner cloud solutionsSwiss Open Telekom CloudReferencesPartnerCIRCLE PartnerTECH PartnerBecome a partnerAcademyTraining & certificationsEssentials trainingFundamentals training coursePractitioner online self-trainingArchitect training courseCertificationsCommunityCommunity blogsCommunity eventsLibraryStudies and whitepaperWebinarsBusiness NavigatorSupportSupport from expertsAI chatbotShared ResponsibilityGuidelines for Security Testing (Penetration Tests)Mobile AppHelp toolsFirst stepsTutorialStatus DashboardFAQTechnical documentationNewsBlogFairs & eventsTrade pressPress inquiriesCommunity

0800 3304477 24 hours a day, seven days a week

Write an E-mail 

Book now and claim starting credit of EUR 250
ProductsCore ServicesPrivate CloudManaged ServicesBenefitsPricesPricing modelsPrice calculatorSolutionsIndustriesUse CasesTurnkey solutionsSwiss Open Telekom CloudReferencesPartnerCIRCLE PartnerTECH PartnerBecome a partnerAcademyTraining & certificationsCommunityLibraryBusiness NavigatorSupportSupport from expertsHelp toolsTechnical documentationNewsBlogFairs & eventsTrade pressPress inquiries
  • 0800 330447724 hours a day, seven days a week
  • Write an E-mail 
Book now and claim starting credit of EUR 250

Configure fine grained access rights for Key Management Service via IAM

With the latest update of the Key Management Service, you can now also configure very detailed permissions on the Key Management Service. You can now also set fine-grained permissions via the "Custom Policy Designer", which is available to you in the IAM Service in the "Permissions" tab via "Create Custom Policy".

The "Custom Policy Designer" allows you to define permissions for specific "actions". This can be the permission to e.g. "create customer keys" or "disable customer keys". You can select from a total 28 actions which can be assigned to your custom policy. Permissions on "actions" can not only be "granted" but also explicitly forbidden.

Furthermore, it is possible to limit the access rules to specific resources. This allows you to define different action permissions for different users/user groups on different customer keys. The permission policy can be linked to further conditional parameters. Those criteria must first be met before the user is then allowed to perform the corresponding action. For example, permissions can be bound to time periods. This allows you to issue permissions only for certain periods of time, so that they expire at a certain given time.

Below you will find the short overview of the update again

Permissions can be

  1. set up on action level (28 individual actions in total)
  2. allowed or explicitly forbidden
  3. dedicated to buckets or objects
  4. linked to conditional parameters

Further information can be found in the Open Telekom Cloud help center.

KMS - https://docs.otc.t-systems.com/en-us/kms/index.html

IAM - https://docs.otc.t-systems.com/en-us/iam/index.html

An example setup with 3 use cases can be found as a post in the Open Telekom Cloud Community via the following link:

https://community.open-telekom-cloud.com/community?id=community_blog&sys_id=4fce7e1e13bd4d14d15a246ea6744179

Back to overview Release Notes 
 

Do you have questions?

We answer your questions about testing, booking and use – free of charge and individually. Try it! 
Hotline: 24 hours a day, 7 days a week
0800 3304477 from Germany / 00800 33044770 from abroad

Write an E-mail

The Open Telekom Cloud Community

This is where users, developers and product owners meet to help each other, share knowledge and discuss.

Discover now

Free expert hotline

Our certified cloud experts provide you with personal service free of charge.

 0800 3304477 (from Germany)

 +800 33044770 (from abroad)

 24 hours a day, seven days a week

Write an E-Mail

Our customer service is available free of charge via E-Mail

Write an E-Mail

AIssistant

Our AI-powered search helps with your cloud needs.