1.0 OCI Connection Permissions
This article describes the read permissions required to onboard an Oracle Cloud Infrastructure (OCI) connection in Fortanix Key Insight. It provides a detailed list of the permissions required to securely integrate with OCI keys and services.
In the policy statements in this document:
Replace
<group_name>with the name of the OCI Identity and Access Management (IAM) group used for the connection.For compartment-level policies, replace
<compartment_name>with the name of the compartment containing the resources to be scanned.
NOTE
Fortanix Key Insight does not have access to customer data. The permissions described in this article are used exclusively to discover and assess cryptographic assets and their security enforcement.
1.1 Compartment-Level Scoping
Use the following policies to provide read access to resources in specific compartments.
OCI Service | IAM Policy | Description |
|---|---|---|
Identity and Compartments |
| Provides access to compartment metadata and hierarchy for identifying resources within the specified compartment. |
Key Management System (KMS) |
| Provides access to vault metadata and information about the vaults available in the specified compartment. |
| Provides access to key metadata and configuration details for assessing keys in the specified compartment. | |
Object Storage |
| Provides access to bucket metadata and configuration information for assessing Object Storage resources in the specified compartment. |
File Storage |
| Provides access to file system metadata and configuration information for assessing file systems in the specified compartment. |
1.2 Tenancy-Level Scoping
Use the following policies to provide read access to resources across the tenancy.
OCI Service | IAM Policy | Description |
|---|---|---|
Identity and Compartments |
| Provides read access to compartment metadata across the tenancy. |
Key Management System (KMS) |
| Provides read access to vault metadata and information across the tenancy. |
| Provides read access to key metadata and configuration across the tenancy. | |
Object Storage |
| Provides read access to bucket metadata across the tenancy. |
File Storage |
| Provides access to file system metadata across the tenancy. |