|
|
|
|
|
by randomv
3104 days ago
|
|
There's a few different revocation options: * `grant-computer` creates a KMS grant as per http://docs.aws.amazon.com/kms/latest/developerguide/grants.... .
`revoke-computer` removes the grant without touching the keys. * The AWS access keys for the IAM user the tool uses, which can be rotated, revoked, recreated, etc... * The per-disk encryption key, which can be deleted from DynamoDB * The KMS CMK, which can be deleted, disabled, etc... I mainly wanted to solve having to plug in a keyboard and type something in, or having a key on a USB stick and be diligent enough to take it out of the home. |
|