<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>服务器安全维护工作室 &#187; Amazon AWS IAM</title>
	<atom:link href="https://www.fuwuqiok.com/tag/amazon-aws-iam/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.fuwuqiok.com</link>
	<description></description>
	<lastBuildDate>Sun, 01 Mar 2020 07:28:40 +0000</lastBuildDate>
	<language>zh-CN</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=4.2.26</generator>
	<item>
		<title>Amazon AWS IAM用户</title>
		<link>https://www.fuwuqiok.com/amazon-aws-iam%e7%94%a8%e6%88%b7/</link>
		<comments>https://www.fuwuqiok.com/amazon-aws-iam%e7%94%a8%e6%88%b7/#comments</comments>
		<pubDate>Fri, 31 Jul 2015 13:25:48 +0000</pubDate>
		<dc:creator><![CDATA[admin]]></dc:creator>
				<category><![CDATA[Amazon AWS]]></category>
		<category><![CDATA[Amazon AWS IAM]]></category>
		<category><![CDATA[Amazon AWS IAM用户]]></category>
		<category><![CDATA[aws服务器代维]]></category>
		<category><![CDATA[IAM]]></category>

		<guid isPermaLink="false">https://www.fuwuqiok.com/?p=2229</guid>
		<description><![CDATA[<p>AWS Identity and Access Management (IAM) 是一项 Web 服务，可使A [&#8230;]</p>
<p><a rel="nofollow" href="https://www.fuwuqiok.com/amazon-aws-iam%e7%94%a8%e6%88%b7/">Amazon AWS IAM用户</a>，首发于<a rel="nofollow" href="https://www.fuwuqiok.com">服务器安全维护工作室</a>。</p>
]]></description>
				<content:encoded><![CDATA[<p>AWS Identity and Access Management (IAM) 是一项 Web 服务，可使AWS用户在 AWS 中管理用户和用户许可。该服务主要针对拥有多用户或多系统且使用 AWS 产品（例如 Amazon EC2、Amazon SimpleDB 及 AWS 管理控制台）的组织。借助 IAM，可以集中管理用户、安全证书（例如访问密钥），以及控制用户可访问哪些 AWS 资源的许可权限。</p>
<p>在这里就以创建只读（readonly）权限的用户为例。探讨一下，AWS 如何创建IAM用户。</p>
<h2>创建IAM用户。</h2>
<p><strong>1.1登陆AWS管理控制台，点击「Identity and Access Management」。</strong><br />
<a href="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Identity-and-Access-Management.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Identity-and-Access-Management.png" alt="Identity-and-Access-Management" width="1403" height="704" /></a><br />
<strong><br />
1.2点击「Users」，然后点击「Create New Users」创建用户。</strong><br />
<a href="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Create-New-Users.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Create-New-Users.png" alt="Create-New-Users" width="1424" height="746" /></a><br />
<strong><br />
1.3如下对话框，可以同时做成5个用户，在最上面的空格里输入要创建的用户名，这里为「fuwuqi120test」。点击「Create」。</strong><br />
<a href="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Enter-User-Names.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Enter-User-Names.png" alt="Enter-User-Names" width="1424" height="837" /></a><br />
<strong><br />
1.4如下窗口显示用户创建成功。点击「Download Credentials」，然后点击「Close」关闭。Credential.csv里记载了用户名和使用API时的访问键和密钥。密钥仅在此次创建时取得，如果忘记下载，或者丢失，需要重新做成。</strong><br />
<a href="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Download-Credentials.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Download-Credentials.png" alt="Download-Credentials" width="1420" height="839" /></a></p>
<h2>设置为可登陆的用户。</h2>
<p><strong>2.1通过「User」画面，点击新创建的用户。</strong><br />
<a href="https://www.fuwuqiok.com/wp-content/uploads/2015/07/User-Name.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2015/07/User-Name.png" alt="User-Name" width="1426" height="750" /></a><br />
<strong><br />
2.2选择「Manage Password」。<br />
<a href="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Manage-Password.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Manage-Password.png" alt="Manage-Password" width="1409" height="794" /></a><br />
<strong><br />
2.3显示如下窗口，点击「Apply」。</strong><br />
<a href="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Assign-an-auto-geaerated-password.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Assign-an-auto-geaerated-password.png" alt="Assign-an-auto-geaerated-password" width="1424" height="800" /></a><br />
<strong><br />
2.4如下密码创建成功，然后点击「Download Credentials」，下载Credential.csv文件。</strong><br />
<a href="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Download-Credentials..png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Download-Credentials..png" alt="Download-Credentials." width="1421" height="799" /></a><br />
<strong><br />
如下，显示该用户登陆链接和密码。Credential.csv文件和刚才的内容不一样，这里包含登陆的URL，密码也是仅在本次创建时获得，如果忘记下载，或丢失，需要重新做成。</strong><br />
<a href="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Credential.csv.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Credential.csv.png" alt="Credential.csv" width="628" height="105" /></a></strong></p>
<h2>权限的设定</h2>
<p>至此新创建的用户，除了登陆之外，其他操作全部都是失败的，这里设定只读（Readonly）权限，也可根据自己的需要设定合适的权限。<br />
<strong><br />
3.1从「permissions」所示画面，点击「Attach User Policy」。</strong></p>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Attach-User-Policy.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Attach-User-Policy.png" alt="Attach-User-Policy" width="1414" height="801" /></a><br />
<strong><br />
3.2选择权限，这里选择「Read Only Access」。点击「Select」。</strong><br />
<a href="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Set-Permissons.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Set-Permissons.png" alt="Set-Permissons" width="1410" height="796" /></a><br />
<strong><br />
3.3如下显示了「policy」的内容，可以进行修改，这里直接点击「Apply Policy」。</strong><br />
<a href="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Set-Permissons-name.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Set-Permissons-name.png" alt="Set-Permissons-name" width="1415" height="788" /></a><br />
<strong><br />
3.4实际登陆确认，登录后试着终止EC2实例。会显示如下错误信息。</strong><br />
<a href="https://www.fuwuqiok.com/wp-content/uploads/2015/07/login-test.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2015/07/login-test.png" alt="login-test" width="803" height="649" /></a></p>
<h2>删除用户</h2>
<p><strong>4.1要删除用户时，选择该用户，点击「User Actions」选择「Delete User」。删除该用户。</strong><br />
<a href="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Delete-User.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Delete-User.png" alt="Delete-User" width="1423" height="795" /></a><br />
<strong><br />
4.2点击「Yes　Delete」确定删除该用户。</strong><br />
<a href="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Uaer-Delete.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2015/07/Uaer-Delete.png" alt="Uaer-Delete" width="750" height="194" /></a></p>
<p>&nbsp;</p>
<p><a rel="nofollow" href="https://www.fuwuqiok.com/amazon-aws-iam%e7%94%a8%e6%88%b7/">Amazon AWS IAM用户</a>，首发于<a rel="nofollow" href="https://www.fuwuqiok.com">服务器安全维护工作室</a>。</p>
]]></content:encoded>
			<wfw:commentRss>https://www.fuwuqiok.com/amazon-aws-iam%e7%94%a8%e6%88%b7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
