AWS ebs: Document default EBS encryption key and how to change it
Summary
Adds a new 'Default encryption key' section explaining that EBS auto-creates an AWS managed KMS key (alias aws/ebs) per Region, and provides console, AWS CLI, and PowerShell steps to change the default encryption key to a customer managed key.
Security assessment
The added content documents EBS default encryption behavior and how to switch to a customer managed KMS key, which is encryption/key-management guidance rather than a fix for a specific vulnerability.
Evidence
+Amazon EBS automatically creates a unique AWS managed key in each Region where you create Amazon EBS resources. The alias for this KMS key is `aws/ebs`. This is your default encryption key. You can change the default encryption key to a customer managed key.
Diff
diff --git a/ebs/latest/userguide/encryption-by-default.md b/ebs/latest/userguide/encryption-by-default.md index 7f7ac3163..c69878019 100644 --- a//ebs/latest/userguide/encryption-by-default.md +++ b//ebs/latest/userguide/encryption-by-default.md @@ -6,0 +7,2 @@ +Default encryption key + @@ -183,0 +186,42 @@ You can't change the KMS key that is associated with an existing snapshot or enc +## Default encryption key + +Amazon EBS automatically creates a unique AWS managed key in each Region where you create Amazon EBS resources. The alias for this KMS key is `aws/ebs`. This is your default encryption key. You can change the default encryption key to a customer managed key. + +To change the default encryption key for a Region, use one of the following methods. + +Console + + +###### To change the default encryption key for a Region + + 1. Open the Amazon EC2 console at [https://console.aws.amazon.com/ec2/](https://console.aws.amazon.com/ec2/). + + 2. From the navigation bar, select the Region. + + 3. From the navigation pane, select **Settings** , and then select the **Data protection and security** tab. + + 4. In the **EBS encryption** section, choose **Manage**. + + 5. For **Default encryption key** , select the KMS key ID that you want to use. + + 6. Choose **Update EBS encryption**. + + + + +AWS CLI + + +Use the [modify-ebs-default-kms-key-id](https://docs.aws.amazon.com/cli/latest/reference/ec2/modify-ebs-default-kms-key-id.html) command. + + + aws ec2 modify-ebs-default-kms-key-id --kms-key-id key-id --region region + +PowerShell + + +Use the [Edit-EC2EbsDefaultKmsKeyId](https://docs.aws.amazon.com/powershell/latest/reference/items/Edit-EC2EbsDefaultKmsKeyId.html) cmdlet. + + + Edit-EC2EbsDefaultKmsKeyId -KmsKeyId key-id -Region region +