mirror of
https://github.com/certbot/certbot.git
synced 2026-08-02 00:22:28 +02:00
Granular permissions (#9922)
Set granular permissions to TXT DNS records with names starting with `_acme-challenge.` only This replaces original policy that is too permissive The `Condition` clause uses [Route 53 resource record set permission](https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/resource-record-sets-permissions.html) Policy tested with Certbot 2.9.0
This commit is contained in:
@@ -19,7 +19,19 @@
|
|||||||
],
|
],
|
||||||
"Resource" : [
|
"Resource" : [
|
||||||
"arn:aws:route53:::hostedzone/YOURHOSTEDZONEID"
|
"arn:aws:route53:::hostedzone/YOURHOSTEDZONEID"
|
||||||
]
|
],
|
||||||
|
"Condition": {
|
||||||
|
"ForAllValues:StringLike": {
|
||||||
|
"route53:ChangeResourceRecordSetsNormalizedRecordNames": [
|
||||||
|
"_acme-challenge.*"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"ForAllValues:StringEquals": {
|
||||||
|
"route53:ChangeResourceRecordSetsRecordTypes": [
|
||||||
|
"TXT"
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user