Configuring access permissions for a digital signature key pair
You can grant access to an asymmetric digital signature key pair to a user, service account, or user group. To do this, assign roles for the digital signature key pair. To choose the ones you need, learn about the existing roles.
Assigning a role
- In the management console
, select the folder containing the asymmetric encryption key pair. - Navigate
to Key Management Service. - In the left-hand panel, select Asymmetric keys.
- On the Signature tab, click the key pair name.
- Navigate to the Access bindings section and click Assign roles.
- Select the group, user, or service account you need to grant access to the key pair.
- Click
Add role and select the roles. - Click Save.
If you do not have the Yandex Cloud CLI yet, install and initialize it.
The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also specify a different folder for any command using --folder-name or --folder-id.
If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
To assign a role for an asymmetric digital signature key pair:
-
View the description of the CLI command for assigning roles:
yc kms asymmetric-signature-key add-access-binding --help -
Get a list of digital signature key pairs with their IDs:
yc kms asymmetric-signature-key list -
Get the ID of the user, service account, user group, organization, or identity federation to which (or to the users of which) you are assigning a role.
-
To assign a role, run this command:
yc kms asymmetric-signature-key add-access-binding \ --id <key_pair_ID> \ --role <role> \ --subject <subject_type>:<subject_ID>Where:
-
--id: ID of the digital signature key pair. -
--role: Role. -
--subject: Subject getting the role.Subject designations
To indicate a subject, use the
--subjectparameter in<subject_type>:<ID>format. For some subject types, the Yandex Cloud CLI provides separate parameters instead of--subject, where you only need to specify the subject name or ID without the type. Possible subject designations and matching CLI parameters:Subject type
Subject designation
Yandex Cloud CLI parameter
userAccountuserAccount:<user_ID>--user-account-idor--user-yandex-loginserviceAccountserviceAccount:<service_account_ID>--service-account-idor--service-account-namefederatedUserfederatedUser:<user_ID>--user-account-idgroupgroup:<group_ID>--group-memberssystemsystem:allAuthenticatedUsers(
All authenticated usersgroup)--all-authenticated-userssystem:allUsers(
All usersgroup)—
system:group:organization:<organization_ID>:users(
All users in organization Xgroup)--organization-userssystem:group:federation:<federation_ID>:users(
All users in federation Ngroup)--federation-userssystem:group:userpool:<pool_ID>:users(
All users in userpool Pgroup)—
-
With Terraform
Terraform is distributed under the Business Source License
For more information about the provider resources, see the guides on the Terraform
If you do not have Terraform yet, install it and configure the Yandex Cloud provider.
To manage infrastructure using Terraform under a service account or user accounts (a Yandex account, a federated account, or a local user), authenticate using the appropriate method.
To assign a role for an asymmetric digital signature key pair using Terraform:
-
In the Terraform configuration file, describe the resources you want to create:
resource "yandex_kms_asymmetric_signature_key_iam_member" "key-viewers" { asymmetric_signature_key_id = "<key_pair_ID>" role = "<role_1>" member = "<subject_type>:<subject_ID>" }Where:
-
asymmetric_signature_key_id: ID of the digital signature key pair. -
role: Role. -
member: Subject getting the role.Subject designations
To indicate a subject, use a combination of its type and unique ID, i.e.,
<subject_type>:<ID>. Here is how you can designate a subject:Subject type
Subject designation
userAccountuserAccount:<user_ID>serviceAccountserviceAccount:<service_account_ID>federatedUserfederatedUser:<user_ID>groupgroup:<group_ID>systemsystem:allAuthenticatedUsers(
All authenticated usersgroup)system:allUsers(
All usersgroup)system:group:organization:<organization_ID>:users(
All users in organization Xgroup)system:group:federation:<federation_ID>:users(
All users in federation Ngroup)system:group:userpool:<pool_ID>:users(
All users in userpool Pgroup)
For more on the properties of the
yandex_kms_asymmetric_signature_keyresource, see this provider guide. -
-
Create the resources:
-
In the terminal, navigate to the configuration file directory.
-
Make sure the configuration is correct using this command:
terraform validateIf the configuration is valid, you will get this message:
Success! The configuration is valid. -
Run this command:
terraform planYou will see a list of resources and their properties. No changes will be made at this step. Terraform will show any errors in the configuration.
-
Apply the configuration changes:
terraform apply -
Type
yesand press Enter to confirm the changes.
Terraform will create all the required resources. You can check the new resources using this CLI command:
yc kms asymmetric-signature-key list-access-bindings <key_pair_ID> -
Use the updateAccessBindings method for the AsymmetricSignatureKey resource or the AsymmetricSignatureKeyService/UpdateAccessBindings gRPC API call and provide the following in the request:
-
ADDvalue in theaccess_binding_deltas[].actionparameter to add a role. -
Role in the
access_binding_deltas[].access_binding.role_idparameter. -
ID of the subject getting the role in the
access_binding_deltas[].access_binding.subject.idparameter. -
Type of the subject getting the role in the
access_binding_deltas[].access_binding.subject.typeparameter.Subject designations
To indicate a subject, use a combination of its type and unique ID in the
subject.typeandsubject.idfields of the request. Here are possible combinations:subject.type
subject.id
userAccount<user_ID>serviceAccount<service_account_ID>federatedUser<user_ID>group<group_ID>systemallAuthenticatedUsers(
All authenticated usersgroup)allUsers(
All usersgroup)group:organization:<organization_ID>:users(
All users in organization Xgroup)group:federation:<federation_ID>:users(
All users in federation Ngroup)group:userpool:<pool_ID>:users(
All users in userpool Pgroup)
Assigning multiple roles
- In the management console
, select the folder containing the asymmetric encryption key pair. - Navigate
to Key Management Service. - In the left-hand panel, select Asymmetric keys.
- On the Signature tab, click the key pair name.
- Navigate to the Access bindings section and click Assign roles.
- Select the group, user, or service account you need to grant access to the key pair.
- Click
Add role and select the roles. - Click Save.
Alert
The set-access-bindings command for assigning multiple roles completely overwrites access permissions for the resource. All roles previously assigned for this resource will be deleted.
If you do not have the Yandex Cloud CLI yet, install and initialize it.
The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also specify a different folder for any command using --folder-name or --folder-id.
If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
To assign multiple roles for a digital signature key pair:
-
Make sure the key pair has no roles assigned that you would not want to lose:
yc kms asymmetric-signature-key list-access-bindings \ --id <key_pair_ID> -
View the description of the CLI command for assigning roles:
yc kms asymmetric-signature-key set-access-bindings --help -
Get a list of digital signature key pairs with their IDs:
yc kms asymmetric-signature-key list -
Get the ID of the user, service account, user group, organization, or identity federation to which (or to the users of which) you are assigning roles.
-
To assign roles, run this command:
yc kms asymmetric-signature-key set-access-bindings \ --id <key_pair_ID> \ --access-binding role=<role>,subject=<subject_type>:<subject_ID>Where:
-
--id: ID of the digital signature key pair. -
Where
--access-bindingis the role and the subject the role is assigned to.Subject designations
To indicate a subject, use the
--subjectparameter in<subject_type>:<ID>format. For some subject types, the Yandex Cloud CLI provides separate parameters instead of--subject, where you only need to specify the subject name or ID without the type. Possible subject designations and matching CLI parameters:Subject type
Subject designation
Yandex Cloud CLI parameter
userAccountuserAccount:<user_ID>--user-account-idor--user-yandex-loginserviceAccountserviceAccount:<service_account_ID>--service-account-idor--service-account-namefederatedUserfederatedUser:<user_ID>--user-account-idgroupgroup:<group_ID>--group-memberssystemsystem:allAuthenticatedUsers(
All authenticated usersgroup)--all-authenticated-userssystem:allUsers(
All usersgroup)—
system:group:organization:<organization_ID>:users(
All users in organization Xgroup)--organization-userssystem:group:federation:<federation_ID>:users(
All users in federation Ngroup)--federation-userssystem:group:userpool:<pool_ID>:users(
All users in userpool Pgroup)—
Provide a separate
--access-bindingparameter for each role. Here is an example:yc kms asymmetric-signature-key set-access-bindings \ --id <key_pair_ID> \ --access-binding role=<role1>,subject=<subject_type>:<subject_ID> \ --access-binding role=<role2>,subject=<subject_type>:<subject_ID> \ --access-binding role=<role3>,subject=<subject_type>:<subject_ID> -
With Terraform
Terraform is distributed under the Business Source License
For more information about the provider resources, see the guides on the Terraform
If you do not have Terraform yet, install it and configure the Yandex Cloud provider.
To manage infrastructure using Terraform under a service account or user accounts (a Yandex account, a federated account, or a local user), authenticate using the appropriate method.
To assign multiple roles for an asymmetric digital signature key pair using Terraform:
-
In the Terraform configuration file, describe the resources you want to create:
# Role 1 resource "yandex_kms_asymmetric_signature_key_iam_member" "key-viewers" { asymmetric_signature_key_id = "<key_pair_ID>" role = "<role_1>" member = "<subject_type>:<subject_ID>" } # Role 2 resource "yandex_kms_asymmetric_signature_key_iam_member" "key-editors" { asymmetric_signature_key_id = "<key_pair_ID>" role = "<role_2>" member = "<subject_type>:<subject_ID>" }Where:
-
asymmetric_signature_key_id: ID of the digital signature key pair. -
role: Role. -
member: Subject getting the role.Subject designations
To indicate a subject, use a combination of its type and unique ID, i.e.,
<subject_type>:<ID>. Here is how you can designate a subject:Subject type
Subject designation
userAccountuserAccount:<user_ID>serviceAccountserviceAccount:<service_account_ID>federatedUserfederatedUser:<user_ID>groupgroup:<group_ID>systemsystem:allAuthenticatedUsers(
All authenticated usersgroup)system:allUsers(
All usersgroup)system:group:organization:<organization_ID>:users(
All users in organization Xgroup)system:group:federation:<federation_ID>:users(
All users in federation Ngroup)system:group:userpool:<pool_ID>:users(
All users in userpool Pgroup)
For more on the properties of the
yandex_kms_asymmetric_signature_keyresource, see this provider guide. -
-
Create the resources:
-
In the terminal, navigate to the configuration file directory.
-
Make sure the configuration is correct using this command:
terraform validateIf the configuration is valid, you will get this message:
Success! The configuration is valid. -
Run this command:
terraform planYou will see a list of resources and their properties. No changes will be made at this step. Terraform will show any errors in the configuration.
-
Apply the configuration changes:
terraform apply -
Type
yesand press Enter to confirm the changes.
Terraform will create all the required resources. You can check the new resources using this CLI command:
yc kms asymmetric-signature-key list-access-bindings <key_pair_ID> -
Alert
The setAccessBindings method for assigning multiple roles completely overwrites access permissions for the resource. All roles previously assigned for this resource will be deleted.
Use the SetAccessBindings method for the AsymmetricSignatureKey resource or the AsymmetricSignatureKeyService/SetAccessBindings gRPC API call. In your request, provide an array of objects, each one matching a particular role and containing the following data:
-
Role in the
access_bindings[].role_idparameter. -
ID of the subject getting the roles in the
access_bindings[].subject.idparameter. -
Type of the subject getting the roles in the
access_bindings[].subject.typeparameter.Subject designations
To indicate a subject, use a combination of its type and unique ID in the
subject.typeandsubject.idfields of the request. Here are possible combinations:subject.type
subject.id
userAccount<user_ID>serviceAccount<service_account_ID>federatedUser<user_ID>group<group_ID>systemallAuthenticatedUsers(
All authenticated usersgroup)allUsers(
All usersgroup)group:organization:<organization_ID>:users(
All users in organization Xgroup)group:federation:<federation_ID>:users(
All users in federation Ngroup)group:userpool:<pool_ID>:users(
All users in userpool Pgroup)