AWS marketplace medium security documentation change
Summary
Updated reseller authorization process: replaced dropdown selection with manual AWS account ID entry, added validation instructions, and changed terminology from 'resale authorization' to 'selling authorization'.
Security assessment
Requiring manual entry of 12-digit AWS account IDs instead of dropdown selection reduces misconfiguration risks and potential impersonation attacks. Added validation instructions help prevent erroneous authorization grants. The change mitigates risks of accidental or malicious partner misselection.
Diff
diff --git a/marketplace/latest/userguide/channel-partner-isv-info.md b/marketplace/latest/userguide/channel-partner-isv-info.md index 44959af6e..4ddf55d5f 100644 --- a//marketplace/latest/userguide/channel-partner-isv-info.md +++ b//marketplace/latest/userguide/channel-partner-isv-info.md @@ -11,4 +10,0 @@ Create a selling authorizationManage selling authorizationsSelling authorization -###### Note - -Starting July 1, 2026, ISVs must enter the 12-digit AWS account ID of the intended reseller when creating a selling authorization. The reseller selection dropdown will no longer be available. Resellers can find their account's AWS Account ID by following the guidance on this [AWS Documentation page](https://docs.aws.amazon.com/accounts/latest/reference/manage-acct-identifiers.html). - @@ -48 +44,9 @@ The information you enter in **Selling authorization name** will be visible to C - * For **Reseller** , choose the AWS Marketplace Channel Partner (reseller) that you want to authorize from the dropdown list. You can select resellers by name or account ID. + * For **Reseller** , enter the 12-digit AWS account ID in the available text box. + + * For instructions on validating the 12-digit AWS account ID, see [Validating your AWS account ID](https://awsmarketplace.storylane.io/share/5oeofjaq5s4s) on the AWS Marketplace Storylane website. + + * For instructions on locating your Channel Partner's AWS account ID from previous transactions, see [Locating a Channel Partner's AWS account ID](https://awsmarketplace.storylane.io/share/quvrsa2vqg3v) on the AWS Marketplace Storylane website. + +###### Note + +You can validate the Channel Partner's (reseller) legal entity name in Step 4 (Review and create) of the selling authorization. @@ -82 +86 @@ The information you enter in **Selling authorization description** will be visib -Non-USD currencies are available for contract, contract with consumption, and pay-as-you-go pricing offers. Channel Partners must create offers in the same currency as the resale authorization. +Non-USD currencies are available for contract, contract with consumption, and pay-as-you-go pricing offers. Channel Partners must create offers in the same currency as the selling authorization. @@ -86 +90 @@ Non-USD currencies are available for contract, contract with consumption, and pa - * **Currency restrictions:** CPPOs can only be created in the currency set in the resale authorization. If a Channel Partner wants to extend a CPPO in a different currency, they need to reach out to the ISV to ensure a resale authorization is issued in the new currency. + * **Currency restrictions:** CPPOs can only be created in the currency set in the selling authorization. If a Channel Partner wants to extend a CPPO in a different currency, they need to reach out to the ISV to ensure a selling authorization is issued in the new currency. @@ -94 +98 @@ Non-USD currencies are available for contract, contract with consumption, and pa -The start date for resellers must be earlier than the date that the manufacturer has listed in the resale authorization. +The start date for resellers must be earlier than the date that the manufacturer has listed in the selling authorization.