<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Storing AWS Credentials on an EBS Snapshot Securely</title> <atom:link href="http://shlomoswidler.com/2010/07/storing-aws-credentials-on-an-ebs-snapshot-securely.html/feed" rel="self" type="application/rss+xml" /><link>http://shlomoswidler.com/2010/07/storing-aws-credentials-on-an-ebs-snapshot-securely.html</link> <description>Cloud Developer Tips: Practical tips for developers of cloud computing applications.</description> <lastBuildDate>Tue, 31 Jan 2012 07:15:49 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>By: shlomo</title><link>http://shlomoswidler.com/2010/07/storing-aws-credentials-on-an-ebs-snapshot-securely.html/comment-page-1#comment-611</link> <dc:creator>shlomo</dc:creator> <pubDate>Wed, 30 Mar 2011 14:57:01 +0000</pubDate> <guid
isPermaLink="false">http://www.shlomoswidler.com/?p=190#comment-611</guid> <description>@Ian Harris,Agreed. Using IAM to create restricted-access credentials is a best practice, and should be employed whenever API access is required.</description> <content:encoded><![CDATA[<p>@Ian Harris,</p><p>Agreed. Using IAM to create restricted-access credentials is a best practice, and should be employed whenever API access is required.</p> ]]></content:encoded> </item> <item><title>By: Ian Harris</title><link>http://shlomoswidler.com/2010/07/storing-aws-credentials-on-an-ebs-snapshot-securely.html/comment-page-1#comment-610</link> <dc:creator>Ian Harris</dc:creator> <pubDate>Wed, 30 Mar 2011 14:06:30 +0000</pubDate> <guid
isPermaLink="false">http://www.shlomoswidler.com/?p=190#comment-610</guid> <description>This is an excellent guide. We&#039;ve used this approach and taking it one step further. If you know exactly what the AWS user needs to do you can restrict that user&#039;s actions by using keys that belong to an IAM user configured just for those actions.For example if, as part of instance boot, you have a requirement to download from S3 you could auth using an IAM user restricted to using just that bucket to list and get objects. If your instance is then compromised (even as root) the keys present can do no more damage than show what is already on the instance.The utility of the approach is limited by your use case but it&#039;s a handy way to stop a compromised instance allowing someone to get the keys to the kingdom.</description> <content:encoded><![CDATA[<p>This is an excellent guide. We&#8217;ve used this approach and taking it one step further. If you know exactly what the AWS user needs to do you can restrict that user&#8217;s actions by using keys that belong to an IAM user configured just for those actions.</p><p>For example if, as part of instance boot, you have a requirement to download from S3 you could auth using an IAM user restricted to using just that bucket to list and get objects. If your instance is then compromised (even as root) the keys present can do no more damage than show what is already on the instance.</p><p>The utility of the approach is limited by your use case but it&#8217;s a handy way to stop a compromised instance allowing someone to get the keys to the kingdom.</p> ]]></content:encoded> </item> <item><title>By: Henri Sack</title><link>http://shlomoswidler.com/2010/07/storing-aws-credentials-on-an-ebs-snapshot-securely.html/comment-page-1#comment-401</link> <dc:creator>Henri Sack</dc:creator> <pubDate>Wed, 18 Aug 2010 17:13:48 +0000</pubDate> <guid
isPermaLink="false">http://www.shlomoswidler.com/?p=190#comment-401</guid> <description>Thank you for this tip.
I&#039;ve been searching for such solution for a while !...</description> <content:encoded><![CDATA[<p>Thank you for this tip.<br
/> I&#8217;ve been searching for such solution for a while !&#8230;</p> ]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: basic (User agent is rejected)
Database Caching 2/7 queries in 0.004 seconds using disk: basic
Object Caching 281/284 objects using disk: basic
Content Delivery Network via Amazon Web Services: S3: blogstatic.shlomoswidler.com.s3.amazonaws.com

Served from: shlomoswidler.com @ 2012-02-04 22:33:07 -->
