# AWS240 Crypto and Secret Troubleshooting Workbook

Use with the supplied cases. This is a metadata-only, no-create exercise.

## Safety declaration

- Account reference: `[redacted]`
- Region(s):
- UTC start/end:
- Caller role suffix:
- No secret/SecureString/private-key/ciphertext retrieval: Yes / No
- No AWS change: Yes / No

## Case worksheet

Copy once per case.

### Symptom and scope

- Case:
- Exact redacted error/status:
- First failed UTC time:
- User impact:
- Real workload/client caller:
- Account and Region:
- Redacted resource suffix:
- AWS service acting for caller:
- Resource/change owner:

### Layer diagnosis

| Layer | Healthy / failed / unknown / N/A | Safe evidence | Next evidence |
|---|---|---|---|
| Caller/session | | | |
| Account/Region/identifier | | | |
| Resource type/state | | | |
| SCP/RCP/boundary/endpoint | | | |
| Resource/key policy | | | |
| IAM/grant/conditions | | | |
| DNS/network/attachment | | | |
| Version/rotation/deployment | | | |
| Runtime cache/client | | | |

### Controlled response

- Root cause:
- Proof:
- Least-privilege correction:
- Change risk:
- Rollback trigger/action:
- Layer retest:
- End-to-end test:
- Prevention control:
- Unknown facts:

## Concept checks

Explain:

1. Key policy versus IAM policy:
2. Grant versus persistent policy:
3. Key ID versus ARN versus alias:
4. Rotation versus re-encryption:
5. Symmetric versus asymmetric versus HMAC:
6. Encryption context and its secrecy rule:

## Certificate evidence

| Question | Evidence/result |
|---|---|
| Correct Region for endpoint? | |
| Type/export behavior? | |
| Status and every SAN validation? | |
| Exact CNAME publicly resolvable? | |
| Endpoint in `InUseBy`? | |
| Hostname covered? | |
| Validity and renewal? | |
| Chain/SNI/security policy? | |

## Rotation timeline

| Step | Expected proof | Evidence/result |
|---|---|---|
| `createSecret` | Candidate has `AWSPENDING` | |
| `setSecret` | Target accepts candidate | |
| `testSecret` | Candidate authenticates | |
| `finishSecret` | Candidate is `AWSCURRENT` | |
| Application refresh | Client uses new current | |

## Service choice

| Requirement | Parameter Store | Secrets Manager | Decision/reason |
|---|---:|---:|---|
| Hierarchical configuration | Yes | Not primary | |
| Encrypted static setting | Yes | Yes | |
| Automatic credential rotation | No | Yes | |
| Cross-Region secret replication | No native equivalent | Yes | |
| Advanced parameter policy | Yes | No | |
| Secret staging lifecycle | No | Yes | |

## Cost and closeout

- Pricing pages checked on:
- KMS cost owner:
- Certificate/CA/endpoint cost owner:
- Secret/rotation/replica cost owner:
- Parameter/KMS cost owner:
- Inventory before:
- Inventory after:
- Change events:
- Production changed: No

Write a five-sentence handoff: impact, failing layer, root cause, safest correction, proof/prevention.
