How to Use Amazon S3 Server-Side Encryption for Files and Buckets
CS Browser
Free Windows client for Amazon S3 and Amazon S3 compatible storage services
 
Follow

Amazon S3 Server-Side Encryption

Why Use Amazon S3 Server-Side Encryption?

Server-side encryption protects files at rest. Amazon S3 encrypts each file before writing it to storage and decrypts it when an authorized request reads the file.

Amazon S3 automatically encrypts every new file upload using at least server-side encryption with Amazon S3 managed keys (SSE-S3). You can use CS Browser to apply SSE-S3, SSE-KMS, or, where enabled for the bucket, SSE-C.

Encryption at rest complements, but does not replace, IAM permissions, bucket policies, MFA, HTTPS, and secure credential handling.

How to Check a File's Encryption

Select a file and open the Properties tab. You can also choose Files > Properties.

Properties tab showing the server-side encryption status of a selected file
Select the file and open the Properties tab.

The Server-side encrypted row shows whether Amazon S3 reports SSE-S3, SSE-KMS, or SSE-C for the selected file.

How to Change Encryption for Selected Files

  1. Select the files you want to encrypt or decrypt, then choose Files > Server Side Encryption .. > Encrypt or Decrypt.

    Files menu with Server Side Encryption and Encrypt selected
    Files > Server Side Encryption .. > Encrypt

    If you choose Encrypt, the Choose Server Side Encryption dialog will open:

    Choose Server Side Encryption dialog
    Choose Server Side Encryption dialog
  2. Choose the server-side encryption type and click Apply.

The command is named Decrypt, but it does not store the file unencrypted on Amazon S3. CS Browser copies the file without explicit encryption headers, so Amazon S3 applies the bucket's default encryption, at minimum SSE-S3.

How to Change Encryption for an Entire Bucket

  1. Select the bucket, then choose Buckets > Server Side Encryption .. > Encrypt or Decrypt.

    Buckets menu with Server Side Encryption and Encrypt selected
    Buckets > Server Side Encryption .. > Encrypt
  2. If you choose Encrypt, the Choose Server Side Encryption dialog will open:

    Choose Server Side Encryption dialog
    Choose Server Side Encryption dialog
  3. Choose the server-side encryption type and click Apply.

Changing encryption for an entire bucket is available in CS Browser Pro. CS Browser processes every file by creating a copy with the selected encryption settings. This operation may take some time for a large bucket.

In a versioning-enabled bucket, changing encryption creates a new version of each processed file. Standard Amazon S3 copy request charges and, when using SSE-KMS, AWS KMS request charges may apply.

With CS Browser Pro, you can increase the number of concurrent tasks and process files faster.

How to Apply Encryption Automatically

CS Browser Server-Side Encryption Rules apply the selected request encryption to matching uploads made by this installation. The rules are stored locally on the current computer.

You can create rules for particular files, folders, buckets, or all buckets in an account. SSE-C rules are also supported when SSE-C is enabled for the destination bucket.

Amazon S3 Default Bucket Encryption is enforced by Amazon S3 for uploads from any client when the upload request does not specify another encryption type. It is configured for an entire bucket rather than for individual files or folders.

SSE-C cannot be configured as Amazon S3 Default Bucket Encryption.

Note: SSE-C is disabled by default for new general-purpose buckets. Before using SSE-C in CS Browser, enable it in the bucket's encryption configuration using another AWS management tool or API.

CS Browser 13.5.5 Freeware
Powered by Amazon Web Services and Rated by CNET Editors!
Social Connection
 
People like CS Browser!
People like us
Our customers say

"CS Browser is an invaluable tool to me as a web developer to easily manage my automated site backups" -Bob Kraft, Web Developer

"Just want to show my appreciation for a wonderful product. I use CS Browser a lot, it is a great tool." -Gideon Kuijten, Pro User

"Thank You Thank You Thank You for this tool. A must have for anyone using Amazon S3!" -Brian Cummiskey, USA

Related Products
RdpGuard
protects your Windows Server from RDP Brute-force Attacks.
CS Browser is developed by Netsdk Software FZE and is not affiliated with, endorsed by, or sponsored by Amazon or AWS. Amazon S3 and Amazon S3 Glacier are trademarks of Amazon.com, Inc. or its affiliates.
Copyright © 2008-2026 Netsdk Software FZE. All rights reserved.  Terms of Use.  Privacy Policy.  Mount Amazon S3 Bucket.  RDP brute-force protection.