You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS IoT Core收紧权限策略后MQTT设备认证失败问题

AWS IoT Core 策略收紧后连接认证失败问题排查

问题场景

设备通过8883端口的MQTT协议向AWS IoT Core发送数据,使用宽松策略(iot:*动作 + *资源)可正常连接,但收紧策略后,仅保留特定资源配置时出现认证失败。已通过CloudWatch日志确认clientId与thingName完全匹配。

可正常生效的策略

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "ConnectIfCertAttachedToAThing",
      "Condition": {
        "Bool": {
          "iot:Connection.Thing.IsAttached": "true"
        },
        "StringEquals": {
          "iot:ClientId": "${iot:Connection.Thing.ThingName}"
        }
      },
      "Effect": "Allow",
      "Action": "iot:*",
      "Resource": "*"
    },
    {
      "Sid": "PublishUnderAttachedThingRoot",
      "Effect": "Allow",
      "Action": "iot:Publish",
      "Resource": "arn:aws:iot:${aws:Region}:${aws:AccountId}:topic/${iot:Connection.Thing.ThingName}/*"
    },
    {
      "Sid": "SubReceiveUnderAttachedThingRoot",
      "Effect": "Allow",
      "Action": "iot:Subscribe",
      "Resource": "arn:aws:iot:${aws:Region}:${aws:AccountId}:topicfilter/${iot:Connection.Thing.ThingName}/*"
    },
    {
      "Sid": "ReceiveMessages",
      "Effect": "Allow",
      "Action": "iot:Receive",
      "Resource": "arn:aws:iot:${aws:Region}:${aws:AccountId}:topic/${iot:Connection.Thing.ThingName}/*"
    }
  ]
}

认证失败的目标策略

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "ConnectIfCertAttachedToAThing",
      "Condition": {
        "Bool": {
          "iot:Connection.Thing.IsAttached": "true"
        },
        "StringEquals": {
          "iot:ClientId": "${iot:Connection.Thing.ThingName}"
        }
      },
      "Effect": "Allow",
      "Action": "iot:*",
      "Resource": [
        "arn:aws:iot:${aws:Region}:${aws:AccountId}:client/${iot:Connection.Thing.ThingName}"
      ]
    },
    {
      "Sid": "PublishUnderAttachedThingRoot",
      "Effect": "Allow",
      "Action": "iot:Publish",
      "Resource": "arn:aws:iot:${aws:Region}:${aws:AccountId}:topic/${iot:Connection.Thing.ThingName}/*"
    },
    {
      "Sid": "SubReceiveUnderAttachedThingRoot",
      "Effect": "Allow",
      "Action": "iot:Subscribe",
      "Resource": "arn:aws:iot:${aws:Region}:${aws:AccountId}:topicfilter/${iot:Connection.Thing.ThingName}/*"
    },
    {
      "Sid": "ReceiveMessages",
      "Effect": "Allow",
      "Action": "iot:Receive",
      "Resource": "arn:aws:iot:${aws:Region}:${aws:AccountId}:topic/${iot:Connection.Thing.ThingName}/*"
    }
  ]
}

问题原因

失败策略的第一个Statement中,Action设置为iot:*,但Resource仅限定为client ARN。iot:*包含了所有IoT动作(如iot:Publish、iot:Subscribe等),这些动作需要对应各自的资源(topic、topicfilter等),而当前配置中该Statement的资源仅覆盖client,导致设备执行publish、subscribe等动作时,权限检查不通过,最终触发认证失败。

修正后的策略

将第一个Statement的Action改为仅iot:Connect,明确该语句仅用于授权设备连接动作,其他动作由后续独立Statement授权:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "ConnectIfCertAttachedToAThing",
      "Condition": {
        "Bool": {
          "iot:Connection.Thing.IsAttached": "true"
        },
        "StringEquals": {
          "iot:ClientId": "${iot:Connection.Thing.ThingName}"
        }
      },
      "Effect": "Allow",
      "Action": "iot:Connect",
      "Resource": "arn:aws:iot:${aws:Region}:${aws:AccountId}:client/${iot:Connection.Thing.ThingName}"
    },
    {
      "Sid": "PublishUnderAttachedThingRoot",
      "Effect": "Allow",
      "Action": "iot:Publish",
      "Resource": "arn:aws:iot:${aws:Region}:${aws:AccountId}:topic/${iot:Connection.Thing.ThingName}/*"
    },
    {
      "Sid": "SubReceiveUnderAttachedThingRoot",
      "Effect": "Allow",
      "Action": "iot:Subscribe",
      "Resource": "arn:aws:iot:${aws:Region}:${aws:AccountId}:topicfilter/${iot:Connection.Thing.ThingName}/*"
    },
    {
      "Sid": "ReceiveMessages",
      "Effect": "Allow",
      "Action": "iot:Receive",
      "Resource": "arn:aws:iot:${aws:Region}:${aws:AccountId}:topic/${iot:Connection.Thing.ThingName}/*"
    }
  ]
}

验证建议

  1. 应用修正后的策略后,重启设备连接
  2. 查看CloudWatch IoT日志,确认无权限拒绝错误
  3. 测试设备的publish、subscribe功能是否正常

内容的提问来源于stack exchange,提问作者Paul V

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.01 20:23:14