Skip to content

Instantly share code, notes, and snippets.

Created April 13, 2017 11:36
Show Gist options
  • Save maxmanders/1924538202b5182b2baca1f2c4990984 to your computer and use it in GitHub Desktop.
Save maxmanders/1924538202b5182b2baca1f2c4990984 to your computer and use it in GitHub Desktop.
KMS Envelope Encryption Using OpenSSL And AWS CLI
$ echo "secret" > secret.txt
$ key_material=$(aws kms generate-data-key --key-id <CMK_key_id> --key-spec AES_256)
$ echo ${key_material} | jq ".CiphertextBlob" | sed 's/"//g' | base64 -d > key.enc
$ export key=$(echo ${key_material} | jq ".Plaintext" | sed 's/"//g' | base64 -d)
$ openssl enc -aes-256-cbc -pass env:key -in secret.txt -out secret.txt.enc
$ rm secret.txt
$ ls
key.enc secret.txt.enc
$ key=$(aws-fd-full kms decrypt --ciphertext-blob fileb://key.enc --output text --query Plaintext | base64 -d)
$ openssl enc -d -aes-256-cbc -pass env:key -in secret.txt.enc -out secret.txt
$ cat secret.txt
$ unset key
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment