Problem description
Key Management Service (KMS) rejects read, upload, and download requests sent to a bucket that uses KMS-managed keys for object encryption.
Causes
You do not have permissions to use the specified customer master key (CMK) managed by KMS.
Examples
This error occurs when you upload an object to a bucket that uses server-side encryption with KMS-managed keys (SSE-KMS) without permission to use the specified CMK ID, or when the request is anonymous.
Solutions
Ensure that you have permission to use the specified CMK ID. For more information, see Server-side encryption.
If the issue persists, contact KMS technical support.
References
该文章对您有帮助吗?