AWS Secrets Manager的Canonical Request是否正确?签名生成失败求助
Let's break down the key issues in your canonical request that are almost certainly causing the signature validation failure:
1. Incorrect URI Path
Your canonical request uses /GetSecretValue as the URI path, but for AWS Secrets Manager's GetSecretValue API, the correct path is / (root path). The specific operation is defined via the X-Amz-Target header, not the URI path. This mismatch is critical—SigV4 validates the exact URI path as part of the signature, so even this small difference will break verification.
2. Case Sensitivity in X-Amz-Target
Your canonical request lists x-amz-target:secretsmanager.getsecretvalue, but the correct value should be secretsmanager.GetSecretValue (note the capitalized GetSecretValue). AWS service target values are case-sensitive, so this lowercase mismatch will cause the signature to be rejected.
3. Double-Check Signed Headers Order
Ensure the order of headers in your SignedHeaders list exactly matches the order of your canonical headers. Your current list is accept-encoding;content-type;host;x-amz-content-sha256;x-amz-date;x-amz-target—confirm your canonical headers are listed in this exact sequence (case doesn't matter here, but order absolutely does).
4. Validate Request Payload Hash
Verify that the SHA256 hash you're using (beaead3198f7da1e70d03ab969765e0821b24fc913697e929e726aeaebf0eba3) is computed from the exact request body. Your example body includes a trailing comma:
{ "SecretId": "MyTestDatabaseSecret", }
Make sure you're including this exact content—trailing comma, whitespace, line breaks and all—when calculating the hash. Even a single missing or extra character will produce an invalid hash.
Corrected Canonical Request Example
Here's how your canonical request should look after fixing these issues:
POST / accept-encoding:identity content-type:application/x-amz-json-1.1 host:secretsmanager.sa-east-1.amazonaws.com x-amz-content-sha256:beaead3198f7da1e70d03ab969765e0821b24fc913697e929e726aeaebf0eba3 x-amz-date:20230111T145646Z x-amz-target:secretsmanager.GetSecretValue accept-encoding;content-type;host;x-amz-content-sha256;x-amz-date;x-amz-target beaead3198f7da1e70d03ab969765e0821b24fc913697e929e726aeaebf0eba3
Regenerate the signature in Postman with these fixes and test again—this should resolve the signature failure.
内容的提问来源于stack exchange,提问作者knowledge_eater

