AWS IoT Core收紧权限策略后MQTT设备认证失败问题
AWS IoT Core 策略收紧后连接认证失败问题排查
问题场景
设备通过8883端口的MQTT协议向AWS IoT Core发送数据,使用宽松策略(iot:*动作 + *资源)可正常连接,但收紧策略后,仅保留特定资源配置时出现认证失败。已通过CloudWatch日志确认clientId与thingName完全匹配。
可正常生效的策略
{ "Version": "2012-10-17", "Statement": [ { "Sid": "ConnectIfCertAttachedToAThing", "Condition": { "Bool": { "iot:Connection.Thing.IsAttached": "true" }, "StringEquals": { "iot:ClientId": "${iot:Connection.Thing.ThingName}" } }, "Effect": "Allow", "Action": "iot:*", "Resource": "*" }, { "Sid": "PublishUnderAttachedThingRoot", "Effect": "Allow", "Action": "iot:Publish", "Resource": "arn:aws:iot:${aws:Region}:${aws:AccountId}:topic/${iot:Connection.Thing.ThingName}/*" }, { "Sid": "SubReceiveUnderAttachedThingRoot", "Effect": "Allow", "Action": "iot:Subscribe", "Resource": "arn:aws:iot:${aws:Region}:${aws:AccountId}:topicfilter/${iot:Connection.Thing.ThingName}/*" }, { "Sid": "ReceiveMessages", "Effect": "Allow", "Action": "iot:Receive", "Resource": "arn:aws:iot:${aws:Region}:${aws:AccountId}:topic/${iot:Connection.Thing.ThingName}/*" } ] }
认证失败的目标策略
{ "Version": "2012-10-17", "Statement": [ { "Sid": "ConnectIfCertAttachedToAThing", "Condition": { "Bool": { "iot:Connection.Thing.IsAttached": "true" }, "StringEquals": { "iot:ClientId": "${iot:Connection.Thing.ThingName}" } }, "Effect": "Allow", "Action": "iot:*", "Resource": [ "arn:aws:iot:${aws:Region}:${aws:AccountId}:client/${iot:Connection.Thing.ThingName}" ] }, { "Sid": "PublishUnderAttachedThingRoot", "Effect": "Allow", "Action": "iot:Publish", "Resource": "arn:aws:iot:${aws:Region}:${aws:AccountId}:topic/${iot:Connection.Thing.ThingName}/*" }, { "Sid": "SubReceiveUnderAttachedThingRoot", "Effect": "Allow", "Action": "iot:Subscribe", "Resource": "arn:aws:iot:${aws:Region}:${aws:AccountId}:topicfilter/${iot:Connection.Thing.ThingName}/*" }, { "Sid": "ReceiveMessages", "Effect": "Allow", "Action": "iot:Receive", "Resource": "arn:aws:iot:${aws:Region}:${aws:AccountId}:topic/${iot:Connection.Thing.ThingName}/*" } ] }
问题原因
失败策略的第一个Statement中,Action设置为iot:*,但Resource仅限定为client ARN。iot:*包含了所有IoT动作(如iot:Publish、iot:Subscribe等),这些动作需要对应各自的资源(topic、topicfilter等),而当前配置中该Statement的资源仅覆盖client,导致设备执行publish、subscribe等动作时,权限检查不通过,最终触发认证失败。
修正后的策略
将第一个Statement的Action改为仅iot:Connect,明确该语句仅用于授权设备连接动作,其他动作由后续独立Statement授权:
{ "Version": "2012-10-17", "Statement": [ { "Sid": "ConnectIfCertAttachedToAThing", "Condition": { "Bool": { "iot:Connection.Thing.IsAttached": "true" }, "StringEquals": { "iot:ClientId": "${iot:Connection.Thing.ThingName}" } }, "Effect": "Allow", "Action": "iot:Connect", "Resource": "arn:aws:iot:${aws:Region}:${aws:AccountId}:client/${iot:Connection.Thing.ThingName}" }, { "Sid": "PublishUnderAttachedThingRoot", "Effect": "Allow", "Action": "iot:Publish", "Resource": "arn:aws:iot:${aws:Region}:${aws:AccountId}:topic/${iot:Connection.Thing.ThingName}/*" }, { "Sid": "SubReceiveUnderAttachedThingRoot", "Effect": "Allow", "Action": "iot:Subscribe", "Resource": "arn:aws:iot:${aws:Region}:${aws:AccountId}:topicfilter/${iot:Connection.Thing.ThingName}/*" }, { "Sid": "ReceiveMessages", "Effect": "Allow", "Action": "iot:Receive", "Resource": "arn:aws:iot:${aws:Region}:${aws:AccountId}:topic/${iot:Connection.Thing.ThingName}/*" } ] }
验证建议
- 应用修正后的策略后,重启设备连接
- 查看CloudWatch IoT日志,确认无权限拒绝错误
- 测试设备的publish、subscribe功能是否正常
内容的提问来源于stack exchange,提问作者Paul V
相关产品推荐
相关产品推荐

