-
[AWS
AWS STS - Security Token Service
- Allows to grant limited and temporary access to AWS resource (up to 1 hour)
- AssumeRole: Assume roles within your account or cross account
- GetSessionToken: for MFA, from a user or AWS account root user
- DecodeAuthorizationMessage: decode error message when an AWS API is denied
- AssumeRoleWithSAML: return credentials for users logged with SAML
- GetRederationToken: obtaini temporary creds for a federated user
- GetCallerIdentity: return details about the IAM user or role userd in the API called
STS with MFA
- User GetSessionToken from STS
- Appropriate IAM policy using IAM conditions
- aws:MultiFactorAuthPresent: true
- Reminder, GetSessionToken
- return:
- AccessID
- Secrect Key
- SessionToken
- Expiration date
![](https://img2020.cnblogs.com/blog/364241/202106/364241-20210613024920021-742032706.png)
IAM Policies & S3 Bucket Policies
- IAM Policies are attached to user, roles, groups
- S3 Bukcet Policies are attached to bucekts
- When evaluating if an IAM Principal can perform an operation X on a bucket, the union of its assigned IAM policeis and S3 bucket policies will be evaluated
![](https://img2020.cnblogs.com/blog/364241/202106/364241-20210613025541585-1296920434.png)
![](https://img2020.cnblogs.com/blog/364241/202106/364241-20210613025919007-784511343.png)
![](https://img2020.cnblogs.com/blog/364241/202106/364241-20210613030000046-106066960.png)
![](https://img2020.cnblogs.com/blog/364241/202106/364241-20210613030047888-1489902946.png)
![](https://img2020.cnblogs.com/blog/364241/202106/364241-20210613030105904-829418842.png)
![](https://img2020.cnblogs.com/blog/364241/202106/364241-20210613030134253-1297081691.png)
![](https://img2020.cnblogs.com/blog/364241/202106/364241-20210613030221193-350673006.png)
-
相关阅读:
PAT B1027 打印沙漏 (20 分)
PAT B1025 反转链表 (25 分)
PAT B1022 D进制的A+B (20 分)
PAT B1018 锤子剪刀布 (20 分)
PAT B1017 A除以B (20 分)
PAT B1015 德才论 (25 分)
PAT B1013 数素数 (20 分)
PAT B1010 一元多项式求导 (25 分)
HDU 1405 The Last Practice
HDU 1165 Eddy's research II
-
原文地址:https://www.cnblogs.com/Answer1215/p/14879513.html
Copyright © 2020-2023
润新知