AWS Security ChangesHomeSearch

AWS dms: Add IAM role guidance for Kerberos keycache secret (confused deputy)

Service: dms · 2026-09-27 · Documentation medium

File: dms/latest/userguide/cross-service-confused-deputy-prevention.md · Type: iam

Summary

Adds a new section explaining how to create the IAM role used by AWS DMS to retrieve the Kerberos keycache secret from Secrets Manager (KeyCacheSecretIamArn), including a sample trust policy that adds the aws:SourceAccount condition to prevent cross-service confused deputy issues.

Security assessment

Documents a trust-policy best practice (aws:SourceAccount condition) for a role that grants AWS DMS access to secrets, directly mitigating the cross-service confused deputy problem; it is preventive hardening guidance rather than a fix for a specific disclosed vulnerability or incident.

Evidence

+To use Kerberos authentication with a AWS DMS replication instance, you create an IAM role that allows AWS DMS to retrieve the Kerberos keycache file from Secrets Manager, and then specify that role in the `KeyCacheSecretIamArn` parameter of your replication instance.

Diff

diff --git a/dms/latest/userguide/cross-service-confused-deputy-prevention.md b/dms/latest/userguide/cross-service-confused-deputy-prevention.md
index 449bb6526..8221f0f28 100644
--- a//dms/latest/userguide/cross-service-confused-deputy-prevention.md
+++ b//dms/latest/userguide/cross-service-confused-deputy-prevention.md
@@ -7 +7 @@
-IAM roles to use with AWS DMS APIIAM policy to store preflight assessments in Amazon S3Using Amazon DynamoDB as a target endpoint with AWS DMS
+IAM roles to use with AWS DMS APIIAM policy to store preflight assessments in Amazon S3Using Amazon DynamoDB as a target endpoint with AWS DMSIAM role to access the Kerberos keycache secret
@@ -26,0 +27,2 @@ The most effective way to protect against the confused deputy problem is to use
+  * IAM role to access the Kerberos keycache secret for cross-service confused deputy prevention
+
@@ -140,0 +143,36 @@ JSON
+## IAM role to access the Kerberos keycache secret for cross-service confused deputy prevention
+
+To use Kerberos authentication with a AWS DMS replication instance, you create an IAM role that allows AWS DMS to retrieve the Kerberos keycache file from Secrets Manager, and then specify that role in the `KeyCacheSecretIamArn` parameter of your replication instance. For more information, see [Using Kerberos Authentication](./CHAP_Security.Kerberos.html).
+
+The role that you specify in `KeyCacheSecretIamArn` must belong to the same AWS account that creates or modifies the replication instance. Add the `aws:SourceAccount` global condition context key to the role's trust policy so that AWS DMS can assume the role only for replication instances in your own account.
+
+The following example shows a trust policy with a confused deputy condition that is set on an IAM role that allows AWS DMS to retrieve the Kerberos keycache secret for replication instances in the specified account.
+
+JSON
+    
+
+****
+    
+    
+    
+    {
+      "Version":"2012-10-17",
+      "Statement": [
+        {
+          "Sid": "AllowDMSAssumeRoleForKerberosKeycache",
+          "Effect": "Allow",
+          "Principal": {
+            "Service": "dms.amazonaws.com"
+          },
+          "Action": "sts:AssumeRole",
+          "Condition": {
+            "StringEquals": {
+              "aws:SourceAccount": "111122223333"
+            }
+          }
+        }
+      ]
+    }
+    
+    
+