Getting Started with AWS Cloud Connection

Prev Next

1.0 Introduction

This article describes how to configure or onboard the AWS connection to Fortanix Key Insight to scan your cryptographic materials (Keys, Services, and Certificates).

2.0 Terminology Reference

For AWS connection concepts and supported features, refer to AWS Connection Concepts.

3.0 Start the Connection Setup

Before configuring an AWS connection, ensure you can access Fortanix Key Insight.

For information about signing up for Fortanix Armor, creating an Armor account, and accessing Fortanix Key Insight, refer to Getting Started with Key Insight.

You can start the connection setup when you first access Fortanix Key Insight or after you have entered the application.

  • First-time users: When you access Fortanix Key Insight for the first time, the connection setup wizard is displayed automatically. Proceed to Section 5: Select Cloud Provider to select AWS and configure the connection.

  • Existing users: In Fortanix Key Insight, go to Configuration → Connections → CLOUD → ADD CLOUD CONNECTION. Proceed to Section 5: Select Cloud Provider to select AWS and configure the connection.

4.0 Prerequisites

The following are the prerequisites before configuring an AWS connection on Fortanix Key Insight:

4.1 Set Up an AWS Role in an AWS Organization

Before onboarding an AWS connection, perform the steps described in AWS Connection Scanning Configuration to set up your AWS Role in the AWS organization before onboarding an AWS connection.

4.2 IP Whitelisting Requirements in AWS

To enable secure and reliable communication between Fortanix Key Insight and your AWS cloud environment, certain network connections may need to be allowed.

If IP whitelisting is required, retrieve the current Fortanix IP ranges from the Fortanix SaaS IP Ranges endpoint and allow the applicable IP ranges in your firewall or network infrastructure.

For information about Fortanix SaaS IP ranges and how to determine the applicable IP addresses based on traffic direction, region, and service, refer to Fortanix SaaS IP Whitelisting.

IP whitelisting is not mandatory. It is required only if there are network restrictions on your AWS accounts for inbound traffic.

5.0 Select Cloud Provider

Perform the following steps to select the scan type, connection type, and AWS cloud provider:

  1. On the Select Cloud Provider step, select Automated Scan as the scan type.

  2. Under Select connection type, select Cloud Connections. Under Select cloud provider, select Amazon Web Services.

  3. Click NEXT.

    Figure 1: Select the AWS cloud provider

6.0 Set Up Authentication

AWS supports the secret-based and federated authentication methods to control how users and applications obtain credentials to access AWS services.

6.1 Configure Secret-based Authentication

An authentication method in which an application stores long-lived AWS access keys (Access Key ID and Secret Access Key) and uses them directly to sign AWS API requests.

Perform the following steps to add a secret-based AWS authentication:

  1. On the Set Up Authentication step, select the Secret based authentication.

  2. AWS access key: Enter an AWS access key.

  3. AWS secret access key: Enter an AWS secret access key.

    For more information on how to fetch the secret-based authentication credentials, refer to AWS Connection Scanning Configuration.

  4. Click NEXT.

Figure 2: Select AWS secret-based authentication

6.2 Configure Federated Authentication

An authentication method where users or applications access AWS resources using existing credentials from an external identity provider (IdP), such as PingOne or Microsoft Entra ID. This eliminates the need to store long-lived secrets.

AWS commonly uses the following OAuth flows in federated authentication scenarios:

6.2.1 Authorization Code Flow

Used when a user is involved. The user authenticates with the IdP, the application receives an authorization code, and the code is exchanged for tokens (ID, access, and/or refresh tokens).

Fortanix Key Insight supports configuring AWS connections using the Authorization code flow with PingOne and Microsoft Entra ID as the identity providers.

For more information on how to configure the IdPs and obtain the credentials (Client ID, Well-known URL, and Scopes), refer to the following:

NOTE

  • Fortanix Key Insight recommends creating a dedicated user account in the respective IdP for AWS federated authentication. This account is used to authenticate with the IdP or authorization server and to grant the necessary authorization consent during the connection setup.

  • The dedicated user account must remain active, and any modifications to the account will require re-authorization to update and refresh the authentication configuration.

Perform the following steps to add an IdP configuration using the Authorized Code flow:

  1. On the Set Up Authentication step, select Federated authentication.

  2. In the Select Configuration section, click ADD CONFIGURATION to add a new Identity Provider (IdP) configuration.

  3. In the Add New Configuration dialog box, the Authorization code flow option is selected by default.

    1. Name of configuration:Enter a name for the configuration.

    2. Well-known URL:Enter the Well-known URL of your IdP.

    3. Client ID:Enter the Client ID of your IdP.

    4. Scope: Add the required Scope(s). The default scopes are available to select. You can also add custom scopes if they are already configured.

      NOTE

      Ensure to include the offline_access scope when configuring a Microsoft Entra ID IdP.

    5. Click AUTHORIZE.

      A new browser window opens for authorization, depending on the IdP. After you complete the required steps, the new IdP is added to the Select configuration list.

      Figure 3: Add a Configuration using Authorization Code Flow

  4. After adding and selecting the IdP, enter the Amazon Resource Name (ARN)in the Role ARN field.

    For more information on how to fetch the ARN, refer to AWS Connection Scanning Configuration.

    NOTE

    The Role ARN field is visible only if you have added and selected an IdP configured with the Authorization code flow.

  5. Click NEXT.

NOTE

You can also add an IdP using the Authorization code flow by clicking ADD CONFIGURATION in the top-right corner of the Authentication page.

For more information on managing the Federated Authentication IdP configurations, refer to Federated Authentication Identity Provider Configurations.

6.2.2 Client Credentials Flow

Used for machine-to-machine communication. The application authenticates directly with the IdP using its client ID and secret to obtain tokens, with no user interaction required.

API gateway (Optional): In AWS, an API gateway (such as Kong Gateway) validates tokens, signs AWS requests when required, and proxies them to AWS services, providing centralized authentication and authorization.

Fortanix Key Insight supports configuring AWS connections using the Client Credentials flow with Kong as the API Gateway and Okta and Auth0 as supported IdPs.

For more information on configuring the IdPs and obtaining the required credentials, refer to the following:

NOTE

  • A dedicated application registration in each identity provider is required to securely validate tokens.

  • If the IdP configuration is updated (for example, Client ID, Client Secret, Issuer URL, or scopes), re-authorization is required to maintain a valid onboarding configuration.

Perform the following steps to add an IdP configuration using the Client credentials flow:

  1. On the Set Up Authentication step, select Federated authentication.

  2. In the Select Configuration section, click ADD CONFIGURATION to add a new IdP configuration.

  3. In the Add New Configuration dialog box:

    1. Client credentials flow: Select this option to authenticate to GCP services using client credentials.

    2. Name: Enter a name for the configuration.

    3. Client ID: Enter the Client ID of your IdP.

    4. Client Secret: Enter the Client Secret of your IdP.

    5. Well-known URL: Enter the Well-known URL of your IdP.

    6. Scope(s) (optional): Add custom scopes if required.

    7. Add API Gateway URL (Required for AWS connections): Select this check box to enter the API gateway URL. This is the public URL of the API Gateway deployed in your environment (for example, Kong Gateway). You can obtain this URL from your API Gateway deployment or from the administrator managing the gateway.

      Example:

      https://kong.westus2.cloudapp.azure.com:8443/auth0.

    8. Click AUTHORIZE to complete the authorization.

    Figure 4: Add a configuration using Client Credentials flow

  4. After adding and selecting an IdP, click NEXT.

NOTE

  • When adding or editing the configuration, an Authorization Failed error message may appear if authorization cannot be completed due to incorrect credentials, invalid scope, or other configuration issues.

  • You can also add an IdP using the Client credentials flow by clicking ADD CONFIGURATION in the top-right corner of the Authentication page. For more information on managing the Federated Authentication IdP configurations, refer to Federated Authentication Identity Provider Configurations.

7.0 Set Up Cloud Connections

Perform the following steps on the Set Up Cloud Connections step:

  1. AWS cloud connection name: Enter a name of your AWS connection. For example, AWS connection1.

  2. On the Select scope section:

    • Organization: Select this option if you want to onboard an AWS organization. This allows you to onboard all the AWS accounts in the AWS organization.

    • Account: Select this optionif you want to onboard a single AWS account.

  3. Click NEXT.

Figure 5: Configure AWS cloud account in Fortanix Key Insight

8.0 Select AWS Accounts

Perform the following steps to select AWS accounts:

  1. On the Select AWS Accounts step:

    • If you selected Organization scope in the previous step, choose Select All to onboard all AWS accounts in the AWS organization or manually select the accounts you want to onboard.

    • If you selected Account scope, select the single AWS account to scan and onboard that account.

  2. Click NEXT.

    NOTE

    Fortanix Key Insight scans only the AWS metadata and does not access any AWS key material.

    Figure 6: Select AWS accounts

9.0 Select Key Insight Policy

The System Defined Policy is selected by default on the Key Insight Policy step. This policy is designed to facilitate the scanning of keys and services based on predefined key sizes and permitted operations, ensuring compliance with standard security configurations.

Click NEXT to proceed.

Figure 7: Select Key Insight policy

Additionally,

  • Click ADD POLICY to add a new user-defined policy to the policy center.

  • Click to copy and modify a system-defined policy, converting it into a user-defined policy.

For more information on Fortanix Key Insight policies and features, refer to Cryptographic Policy Management.

NOTE

If you change or update the policy instead of the System Defined Policy, you must Rescan the AWS connection to apply the new policy.

10.0 Select External Key Source

On the Select External Key Source step, you can integrate Fortanix Key Insight with an external key source such as Fortanix DSM to enable key correlation and improve key management.

Perform the following steps:

  1. Select any of the following options:

    • Yes, connect now: This option allows you to add an external key source for your AWS cloud connection and correlate keys using the ADD EXTERNAL KEY SOURCE feature. For more information, refer to Getting Started with External Key Source Connection. After adding the Fortanix DSM connection, select it from the list.

      Figure 8: Add external key source

    • No, I’ll connect later: This option allows you to onboard the AWS connection without adding an external key source. You can add it later if needed.

      Figure 9: Onboard AWS connection without an external key source

  2. Click FINISH to complete the AWS connection onboarding.

    NOTE

    After onboarding the AWS connection:

    • View the AWS connection user interface (UI) (Overview, Assessment, Keys, and so on). You can also switch the region at any time using the region switcher drop down located on the top navigation bar. When the region is changed, the UI updates automatically to show the data, connections, and scan results for that region.

      For more information about the AWS connection UI, refer to AWS Connection - User Interface Components.

    • Users with theAccount AdministratorandGroup Administratorroles can manage (edit, delete, rescan) the connection from the Configuration → Connections → CLOUD.

      • Deleting the AWS connection cannot be undone.

    • A group with the same name will be created on the Fortanix IAM Groups page. For more information on Groups, refer to Fortanix Armor Identity and Access Management (IAM).

11.0 Troubleshooting

For information about common issues and troubleshooting steps when configuring Fortanix Key Insight in cloud environments, refer to Cloud Connection Troubleshooting.

Fortanix-logo

4.6

star-ratings

As of August 2025