<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Choosing KMS Key when using S3 as target in Qlik Replicate</title>
    <link>https://community.qlik.com/t5/Qlik-Replicate/Choosing-KMS-Key-when-using-S3-as-target/m-p/1847891#M1192</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;When downloading files dumped on S3, path (s3://&amp;lt;buket&amp;gt;/&amp;lt;qlik_objects_path&amp;gt;/) we get a Forbidden 403 error.&lt;/P&gt;&lt;P&gt;We are using a role that has access to read and download objects from &amp;lt;bucket&amp;gt; (located in AWS "sandbox" account)&lt;/P&gt;&lt;P&gt;The configuration is like following:&lt;BR /&gt;- Qlik EM and RS ec2 machines are located in aws "prod" account, and are using IAM role “role1”&lt;BR /&gt;- "role1" has permission on two KMS keys which are located in aws "sandbox" account, named: “KM1” and “KM2"&lt;BR /&gt;- "role1" has permission to use "KMS1", but not “KMS2”&lt;/P&gt;&lt;P&gt;So we tried using key "KMS1" in S3 endpoint configuration, under "Data Encryption" and selecting "Server-Side encryption with AWS KMS-Managed Keys (SSE-KMS)".&lt;/P&gt;&lt;P&gt;But it seems we can only set the KEY ID and not the full ARN, which means it must be under the same AWS account.&lt;/P&gt;&lt;P&gt;Would like to know:&lt;/P&gt;&lt;P&gt;1. if that's indeed the reason it cannot upload a test file (KMS keys are looked up in the same AWS account EC2 are)&lt;/P&gt;&lt;P&gt;2. if there's any option to change this and be able to provide the full ARN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Mon, 18 Oct 2021 07:46:52 GMT</pubDate>
    <dc:creator>xavier_quintana</dc:creator>
    <dc:date>2021-10-18T07:46:52Z</dc:date>
    <item>
      <title>Choosing KMS Key when using S3 as target</title>
      <link>https://community.qlik.com/t5/Qlik-Replicate/Choosing-KMS-Key-when-using-S3-as-target/m-p/1847891#M1192</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;When downloading files dumped on S3, path (s3://&amp;lt;buket&amp;gt;/&amp;lt;qlik_objects_path&amp;gt;/) we get a Forbidden 403 error.&lt;/P&gt;&lt;P&gt;We are using a role that has access to read and download objects from &amp;lt;bucket&amp;gt; (located in AWS "sandbox" account)&lt;/P&gt;&lt;P&gt;The configuration is like following:&lt;BR /&gt;- Qlik EM and RS ec2 machines are located in aws "prod" account, and are using IAM role “role1”&lt;BR /&gt;- "role1" has permission on two KMS keys which are located in aws "sandbox" account, named: “KM1” and “KM2"&lt;BR /&gt;- "role1" has permission to use "KMS1", but not “KMS2”&lt;/P&gt;&lt;P&gt;So we tried using key "KMS1" in S3 endpoint configuration, under "Data Encryption" and selecting "Server-Side encryption with AWS KMS-Managed Keys (SSE-KMS)".&lt;/P&gt;&lt;P&gt;But it seems we can only set the KEY ID and not the full ARN, which means it must be under the same AWS account.&lt;/P&gt;&lt;P&gt;Would like to know:&lt;/P&gt;&lt;P&gt;1. if that's indeed the reason it cannot upload a test file (KMS keys are looked up in the same AWS account EC2 are)&lt;/P&gt;&lt;P&gt;2. if there's any option to change this and be able to provide the full ARN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2021 07:46:52 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-Replicate/Choosing-KMS-Key-when-using-S3-as-target/m-p/1847891#M1192</guid>
      <dc:creator>xavier_quintana</dc:creator>
      <dc:date>2021-10-18T07:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: Choosing KMS Key when using S3 as target</title>
      <link>https://community.qlik.com/t5/Qlik-Replicate/Choosing-KMS-Key-when-using-S3-as-target/m-p/1927767#M2603</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;KMS key was not supported till Replicate V 6.1 - need to verify its status now. Please open a case for this question to confirm whether KMS keys are supported or not.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;BR /&gt;Orit&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2022 06:38:26 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-Replicate/Choosing-KMS-Key-when-using-S3-as-target/m-p/1927767#M2603</guid>
      <dc:creator>OritA</dc:creator>
      <dc:date>2022-05-09T06:38:26Z</dc:date>
    </item>
  </channel>
</rss>

