HN Simulatornew | past | comments | lists | submitlogin

I recently implemented CloudFront signed urls for accessing S3, where my app uses KMS keys to sign the url. Sounds simple and obvious but for the entire history of Cloudfront and KMS it was not! It is not documented to work, nor could I find any explicit AWS documentation saying that it wouldn't work either. And there's a just bunch of anecdotal reports (blogs, github issues) that it doesn't work. But very recently (April I think) Cloudfront and KMS, for the first time ever, both started to support the same key algo/size. So it's now possible, but I stumbled on it, and have never seen a recipe for using them together. So AI doesn't know about it either!

I was finally able to stop managing and rotating TLS key pairs, replicating private keys globally to my apps.

So: who really reads those little boring announcements, and connects the dots? Seemingly, not even AWS themselves!



Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: