AWS KMS Connector User Guide

Instructions for deploying the AWS KMS Connector to scan for cryptographic assets and deliver findings to the AgileSec Platform for processing and analysis.

Overview

The AWS KMS Connector integrates AWS Key Management Service with Keyfactor's AgileSec Platform. This Connector allows users to discover, inventory, and analyze cryptographic keys managed by AWS KMS across multiple AWS accounts.

What Gets Scanned

The AWS KMS Connector can discover the following cryptographic assets and asset information:

  • Public Key Data: Enumerates all asymmetric (RSA, ECC) KMS keys in a specified AWS region.

  • Key Metadata: Key specification and usage metadata, aliases, and resource tags for each key; public key material is retrieved for asymmetric keys only.

  • Key Aliases: Human-readable alias names associated with keys.

  • Resource Tags: AWS resource tags applied to KMS keys.

Scanned Data Fields

The following data fields are scanned for AWS KMS keys:

Data Category

Data Fields

Identity / location

  • Key ARN

  • Key ID

  • Account + Region

Cryptographic attributes

  • Algorithm (RSA / ECDSA / AES / HMAC)

  • Classification (symmetric / asymmetric)

  • Key size (bits)

  • Key type (public / secret)

  • SHA-256 fingerprint (computed from public-key material for asymmetric keys; from the key ARN for symmetric keys)

  • Supported operations (encrypt / decrypt / sign / verify / key agreement)

  • Supported algorithms list

Public-key detail (asymmetric keys only)

  • RSA: modulus, public exponent

  • ECC: curve, X, Y coordinates

Lifecycle / metadata (from DescribeKey)

  • Key state, enabled flag

  • Issued-at, last-updated date, expiration date (exp only if external)

  • Description

  • Origin (AWS_KMS / EXTERNAL / AWS_CLOUDHSM / EXTERNAL_KEY_STORE)

  • Key manager (AWS / customer)

  • Key spec

  • Whether Multi-region or not

  • Expiration model (when external key)

  • Deletion date and pending deletion window

  • Custom key store ID, CloudHSM cluster ID, external key store (XKS) key ID

Enrichment

  • Aliases (list of alias names)

  • Resource tags (full key/value map)


Prerequisites

Ensure you meet the following requirements to enable scanning.

Network Access

Ensure HTTPS network connectivity from AgileSec platform or remote execution machine to AWS KMS endpoints.

Supported Authentication Methods

The AWS KMS Connector uses AWS Access Key authentication:

  • Access Key ID + Secret Access Key: Standard IAM user credentials scoped to the target AWS account and region.

AWS KMS Required Access Rights

The IAM user or role must have the following AWS KMS permissions:

Permission

Purpose

kms:ListKeys

Enumerate all KMS keys

kms:DescribeKey

Read key metadata (spec, usage, state)

kms:GetPublicKey

Retrieve public key material (asymmetric keys)

kms:ListAliases

List key aliases

kms:ListResourceTags

List resource tags on keys

Remote Execution Requirements

If running the Connector remotely using CLI, the remote execution machine must meet these requirements:

Component

Requirement

Operating System

  • Linux (x86_64, x86_64): Ubuntu 18.04+, RHEL 9+, CentOS 8+, Debian 10+

RAM

Minimum 500 mb (0.5 GB) to enable API calls and data streaming.

Disk Space

Minimal; scans are API-driven and findings are streamed to the AgileSec platform. No data is stored on disk.

Permissions

Read/write access to remote sensor working directory (remote sensor install location)


Running the Connector

AgileSec AWS KMS scans can be executed using the following methods:

  1. Platform Scan Execution: Configure and execute scans directly through the Keyfactor AgileSec web UI with on-demand or scheduled execution options.

  2. API Scan Execution: Programmatically trigger scans through REST API calls, enabling integration with CI/CD pipelines and automation workflows.

  3. Remote Scan Execution: Deploy and run the connector via CLI on customer-managed infrastructure for scenarios such as:

    1. Scanning air-gapped or internal instances the platform cannot directly reach

    2. Customers wanting to manage their own scheduling and execution environment.

Refer to Scan Execution Flows for additional scan execution information.

Connectors/Sensors Note: Connectors are considered a subset of Sensors. Sensors and Connectors utilize the same Unified Sensor Framework, but Sensors use the Host Sensor for additional scanning depth.

“Sensor”-labeled variables for API and Remote execution are common to both Sensors and Connectors. Unless specified, do NOT update these with “Connector”.

Configuration Options

The following parameters are used to configure AgileSec AWS KMS scans.

Field Name

UI Display Name

Type

Required

Description

akid

Access Key ID

String

✅ Yes

AWS Access Key ID for the IAM user

secret_key

Secret Access Key

String

✅ Yes

AWS Secret Access Key for the IAM user

region

AWS Region

String

✅ Yes

AWS region to scan (e.g., us-east-1, eu-west-1)

Platform Scan Execution

Running scans through the user interface is the simplest and fastest way to get started. The platform enables running on-demand or scheduled scans in a dedicated environment.

Platform Scan Configuration

  1. Open your browser and navigate to the Keyfactor AgileSec Platform Web URL

  2. Log in with your credentials

  3. Click on "Sensors" in the left navigation menu under Scan

    image-20260616-210209.png
  4. Click "+ New Sensor".

    image-20260616-210325.png
  5. Click on the correct card to open the configuration interface.

Configure Parameters and Start Scan
  1. Fill in the required configuration parameters.

  2. Click Save.

  3. Click Action then Scan to begin a scan.
    Note: Click Edit to reconfigure parameters.

    image-20260616-214857.png

API Scan Execution

Scans may be programmatically triggered through REST API calls, enabling seamless integration with CI/CD pipelines, automation workflows, and custom applications. API execution provides flexibility for developers to incorporate cryptographic scanning into their existing development and deployment processes.

Note: For complete API reference, see API.

Generate AgileSec API Access Token

  1. Open your browser and navigate to AgileSec Platform UI

  2. Log in with your Keyfactor credentials

  3. Click "Access Tokens" in the main navigation menu

  4. Click "Generate Token" button

  5. Set Token Type to API Token and provide the required details

  6. Click "Generate" and copy the generated token

    image-20260616-212437.png

AgileSec API Endpoint

POST https://<platform-url>/v3/scan/create/

Request Format

Headers
Content-Type: application/json
isg-api-token: <your-api-token>
Request Body
JSON
  {
    "sensorName": "<sensor name>",
    "sensorType": "AWS KMS",
    "sensorConfig": {
       "akid": "<aws access key id>",
       "secret_key": "<aws secret key>",
       "region": "<aws region>"
    },
    "callbackId": "<callback id>",
    "labels": [
        {
            "<label name>": "<label value>"
        }
    ],
    "priority": "<priority>"
  }

Remote Scan Execution

Scans may be run on remote host machines with the AgileSec Remote Sensor Package.

Download Remote Sensor Package
  1. Open your browser and navigate to the Keyfactor AgileSec Platform Web URL

  2. Log in with your credentials

  3. Click on "Sensors" in the left navigation menu under Scan

    image-20260616-210209.png
  4. Click Remote Scan.

    image-20260616-220921.png
  5. Click + Download Remote Sensor.

    image-20260616-221015.png
  6. Download the sensor binary for your remote machine’s operating system

    image-20260616-221050.png
Generate Platform Token
  1. In the Download Remote UI, click "Generate Token"

  2. Copy the generated token

  3. Store securely in an environment variable such as SENSOR_TOKEN:

     export SENSOR_TOKEN="your-generated-token"
    
Create Configuration File

Create a YAML configuration file (e.g., awskms-config.yml) with your scan settings. An example configuration can be found in config/sample-configs/awskms.yml.

Step 4: Run the Connector

Execute the Connector with your configuration file:

  • Linux/macOS

    Bash
    # Set environment variables
    export SENSOR_TOKEN="your-sensor-token"
    
    # Run Connector
    ./unified_sensor_linux -c awskms-config.yml
    
  • Windows (PowerShell)

    PowerShell
    # Set environment variables
    $env:SENSOR_TOKEN = "your-sensor-token"
    
    # Run Connector
    .\\unified_sensor_windows.exe -c .\\awskms-config.yml
    

Remote Scan Execution Configuration Examples

  • Basic Configuration

    YAML
    scan_config:
      plugins:
        - awskms
        - export
      config:
        awskms:
          name: awskms
          plugin_config:
            akid: "${env:AWS_ACCESS_KEY_ID}"
            secret_key: "${env:AWS_SECRET_ACCESS_KEY}"
            region: "us-east-1"
    

Known Limitations

Symmetric Key Material Is Not Extractable

Symmetric KMS keys (SYMMETRIC_DEFAULT and the HMAC_224/256/384/512 specs) are inventoried with their algorithm, size, key usage, and supporting metadata. However, AWS KMS never releases symmetric key material, so these findings carry no raw key bytes. Their fingerprint_sha256 is derived from the immutable key ARN (unique per key, stable across scans) rather than from key material. Only asymmetric keys (RSA, ECC) expose public key material, from which the fingerprint is computed directly.

Single Region

Each scan covers a single AWS region. To scan multiple regions, configure multiple Connector instances.

Troubleshooting Common Errors

  • CONFIG-404 – Unable to read/parse configuration file

    • Cause: The configuration file path is incorrect or the file is malformed.

    • Fix: Verify the config file path and validate JSON syntax.

  • CONFIG-422 – Required attribute not found

    • Cause: A required configuration field (e.g., akid, secret_key, region) is missing.

    • Fix: Ensure all required fields are present in the configuration.

  • AWSKMS-201 – Failed ListKeys

    • Cause: Insufficient IAM permissions or invalid credentials.

    • Fix: Verify IAM permissions include kms:ListKeys and credentials are correct.

  • AWSKMS-202 – Failed GetPublicKey

    • Cause: Unexpected failure retrieving the public key of an asymmetric key; the affected key is skipped. Expected cases (UnsupportedOperationException for keys without public material, AccessDeniedException) are logged without this code

    • Fix: This is expected for symmetric keys. For asymmetric keys, ensure kms:GetPublicKey permission.

  • AWSKMS-205 – Failed DescribeKey

    • Cause: Unexpected failure reading key metadata. Without DescribeKey metadata, the affected key is skipped and cannot be reported. AccessDeniedException is logged without this code.

    • Fix: Ensure kms:DescribeKey permission is granted.

Getting Support

Collect diagnostic information:

  • Sensor version

  • Configuration file (redact credentials)

  • Log output

  • AWS details (region, account ID)

Contact Support