æ¬è¨äºã¯
AWSã¢ã¯ã¼ãè¨å¿µï¼å¤ã®ã¢ããã³ãã«ã¬ã³ãã¼
6æ¥ç®ã®è¨äºã§ãã
ðð
5æ¥ç®
â¶â¶ æ¬è¨äº â¶â¶
7æ¥ç®
ðð
ããã«ã¡ã¯ãé»æ¨ã§ãã
ãAWSã®è³æ ¼ããã¤æã£ã¦ãã®ï¼ã ãå ¨é¨æã£ã¦ã¾ãã ã£ã¦çããããããã«ãªãããã£ãã§ãããæ°ããªèªå®è©¦é¨ãããã¤ãå¢ãããã¨ã§ã¾ã å ã«ãªãããã§ããÙ©( á )Ùカï¾ï¾ï¾ï¾ï¾ï½¿ï¾ï½°
ãã¦ä»åã¯S3ã®MFA Deleteã®æå¹åã¨ç¡å¹åãæ¤è¨¼ãããæãå°ãã¤ã¾ã¥ãããã¤ã³ããããã¾ããã®ã§åå¿ãããã¦æ¸ãããã¨æãã¾ãã
è¦ç´
2024å¹´7æç¾å¨ããã¡ãã®ããã¥ã¡ã³ããè¦ãã¨ä»¥ä¸ã®éãã§ãã
- MFA Deleteã¯ã«ã¼ãã¢ã«ã¦ã³ãããããæå¹åã§ããªãã
- AWS CLIã¾ãã¯APIããããæä½ã§ããªãã
- ã©ã¤ããµã¤ã¯ã«ããªã·ã¼ã¨ä½µç¨ã¯ã§ããªãã
äºåæºå
ä»åã®æ¤è¨¼ã«å¿ è¦ãªãã®ã¯ä»¥ä¸ã«ãªãã¾ãã
対象ã®S3ãã±ãã
- ãã±ããã®ä½ææ¹æ³ã¯çãã¾ãã
MFAããã¤ã¹
- ä»åã¯Google Authenticatorã使ãã¾ãã
ã«ã¼ãã¢ã«ã¦ã³ãã¸ã®ãã°ã¤ã³æ段
MFA Deleteã®æå¹å
ã«ã¼ãã¢ã«ã¦ã³ãã«ãã°ã¤ã³ããç»é²ãã¦ããMFAããã¤ã¹ã®èå¥åã確èªãã¾ããã»ãã¥ãªãã£èªè¨¼æ å ±ã¸ç§»åãMFAã®èå¥åãã¡ã¢ãã¾ãã
ä»ã®ã¨ããã³ã³ã½ã¼ã«ç»é¢ããã¯æå¹åã®å®è¡ãã§ããªãã®ã§ãä»åã¯CloudShellãéãã¾ãã
æå¹åããããã®ã³ãã³ãã¯ä»¥ä¸ã«ãªãã¾ããï¼ä»¥ä¸ã®ã³ãã³ããå®è¡ããã¨ãã¼ã¸ã§ãã³ã°ãç¡å¹åãMFADeleteãæå¹åããã¾ãï¼
aws s3api put-bucket-versioning --bucket <対象ã®S3ãã±ããã®åå> --versioning-configuration Status=Suspended,MFADelete=Enabled --mfa "<MFAã®èå¥å> <ã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ã>"
Statusã¨MFADeleteã®ãã©ã¡ã¼ã¿ã®éã¯ã¹ãã¼ã¹ã空ããã«ã«ã³ãã§ç¹ãã¦è¨è¼ãã¦ãã ããã
ä¸è¨ãå®è¡ããã°MFA Deleteã¯æå¹åããã¾ããæå¹åããããã®ç¢ºèªã¯ä»¥ä¸ã®ã³ãã³ãã§ç¢ºèªãã¾ãã
aws s3api get-bucket-versioning --bucket <対象ã®S3ãã±ããã®åå>
MFA DeleteãEnabledã«ãªã£ã¦ãã®ã§æå¹ã§ããã
ã¾ããMFA Deleteã®è¨å®ç¶æ³ã¯ã³ã³ã½ã¼ã«ä¸ã§ã確èªãããã¨ãã§ãã¾ãã対象ã®S3ãã±ããã®ããããã£ã¿ãã¸ç§»åãããã±ããã®ãã¼ã¸ã§ãã³ã°æ¬ã®ãMulti-Factor Authentication (MFA) ã®åé¤ããæå¹ã¨ãªã£ã¦ããã°è¨å®ã§ãããã¨ã確èªã§ãã¾ãã
ç·¨éã®ãã¿ã³ãããã¾ããã2024å¹´7æç¾å¨ã§ã¯ãã¼ã¸ã§ãã³ã°ã®ããã«ç·¨éã¯ã§ããªãã§ãããã¤ãããã«ã©ã¸ãªãã¿ã³ã追å ããããã¨ãæå¾ ãã¾ãã
æå¹åã®æé ã¯ä»¥ä¸ã§ãããæ¤è¨¼ä¸ããã¤ãã¤ã¾ã¥ããã®ã§ããã®æã®ã¨ã©ã¼ã¨è§£æ±ºçãè¨ãã¾ãã
ã¤ã¾ã¥ããã¤ã³ãï¼
An error occurred (InvalidRequest) when calling the PutBucketVersioning operation: DevPay and Mfa are mutually exclusive authorization methods.
ä¸è¨ã¨ã©ã¼ã¯ã«ã¼ãã¢ã«ã¦ã³ãã§å®è¡ããªãã¨ãã¡ã¨ããæå³ã§ããã¯ããã¯ã©ã®ã¦ã¼ã¶ã¼ã§ãå®è¡ã§ããã¨æã£ã¦ããã®ã§ããã¥ã¡ã³ããããèªããã¨ã¯éè¦ã ã¨çæãã¾ããã ã«ã¼ãã¢ã«ã¦ã³ãã®CloudShellã§å®è¡ããå ´åã¯ã¢ã¯ã»ã¹ãã¼ãçºè¡ãã¦aws configureãå®è¡ãã¦ã«ã¼ãèªè¨¼ãããå¿ è¦ãããã¾ããã¾ããã¢ã¯ã»ã¹ãã¼ã¯MFA Deleteã®ä½æ¥ãå®äºãããå¿ ãåé¤ãã¾ãããã
ã¤ã¾ã¥ããã¤ã³ãï¼
An error occurred (InvalidBucketState) when calling the PutBucketVersioning operation: Mfa Authentication is not supported on a bucket with lifecycle configuration. Delete lifecycle configuration before enabling Mfa Authentication.
ä¸è¨ã®ã¨ã©ã¼ã¯ã©ã¤ããµã¤ã¯ã«ããªã·ã¼ãè¨å®ãã¦ããããMFA Deleteãè¨å®ã§ããªãã¨ãããã®ã§ããå®ã¯MFA Deleteã¨ã©ã¤ããµã¤ã¯ã«ããªã·ã¼ãåæã«è¨å®ãããã¨ã¯ã§ãã¾ããããããã«è¨ããã¦ã¿ãã°ã©ã¤ããµã¤ã¯ã«ããªã·ã¼ã¯æéãæ¥ããèªåã§ãªãã¸ã§ã¯ããåé¤ããè¨å®ã§ã¯ãããã®ã®ãMFAã§ä¿è·ããã¦ãããããªã·ã¼ã§ã¯åé¤ã§ããªãã§ããã
æ¤è¨¼æã®S3ãã±ããã«ã¯ã©ã¤ããµã¤ã¯ã«ããªã·ã¼ãè¨å®ããã¦ããããããããåé¤ãã¦å度å®è¡ãç¡äºã«è¨å®ã§ãã¾ããã
MFA Deleteã®ç¡å¹å
ä»åº¦ã¯ç¡å¹åã§ãããããã¯æå¹åã®æã«ä½¿ã£ãã³ãã³ãã®ãã©ã¡ã¼ã¿å¤ãå¤ããã ãã§ãã
aws s3api put-bucket-versioning --bucket <対象ã®S3ãã±ããã®åå> --versioning-configuration Status=Suspended,MFADelete=Disabled --mfa "<MFAã®èå¥å> <ã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ã>"
versioning-configurationã¯ãã±ããã®ãã¼ã¸ã§ãã³ã°ã¨MFA Deleteã«ã¤ãã¦ã®è¨å®ããããã©ã¡ã¼ã¿ã§ããStatusããã¼ã¸ã§ãã³ã°ã§ãMFADeleteãMFA Deleteã§ãï¼ãã®ã¾ã¾ã§ããï¼ã
ç¡å¹åæã®ãã©ã¡ã¼ã¿å¤ãããããç°ãªããã¨ã«ã注æãã¦ãã ããã
MFADelete | Status | |
---|---|---|
æå¹å | Enabled | Enabled |
ç¡å¹å | Disabled | Suspended |
MFA Deleteã®æå¹ã»ç¡å¹åã«ã¤ãã¦ã¯ä»¥ä¸ã«ãªãã¾ãã
ãããã«
ä»åã¯MFA Deleteã®æå¹ã»ç¡å¹åã®æ¤è¨¼ã§ããã
MFA Deleteã¨åæã«ãã±ããã®ãã¼ã¸ã§ãã³ã°ãæå¹åãã¦ãããæ¹ãããå®å ¨æ§ãé«ã¾ãã¾ãã®ã§ä¸¡æ¹ãã£ã¦ããã¨ããããã§ãã