Burp Suite User Forum

Create new post

BurpSuite Enterprise AWS deployment problems

Ahmed | Last updated: Oct 04, 2021 09:37PM UTC

Hi, I followed the instructions provided in the documentation (https://portswigger.net/burp/documentation/enterprise/getting-started/cloud/deploy-aws#nested-templates) to deploy BurpSuite enterprise to AWS. I used both the AWS IAM CloudFormation template and the AWS main CloudFormation template. I also added my user to the burp-suite-enterprise-edition-CloudFormationUsers user group. I tried to deploy "Enterprise Edition 2021.8.1" and I keep getting the following issues. first issue: both EfsMountTarget1a and EfsMountTarget1b EfsMountTarget CREATE_FAILED Resource handler returned message: "User is not authorized to perform that action on the specified resource (Service: Efs, Status Code: 403, Request ID: [ID here], Extended Request ID: null)" (RequestToken: [token here], HandlerErrorCode: GeneralServiceException) second issue: EksCluster EksCluster CREATE_FAILED Role with arn: arn:aws:iam::[account ID]:role/burp-suite-enterprise-edition-eksClusterRole, could not be assumed because it does not exist or the trusted entity is not correct (Service: AmazonEKS; Status Code: 400; Error Code: InvalidParameterException; Request ID: [request ID here]; Proxy: null) I checked and all the roles to be created by the IAM template was indeed created. I appreciate your help in this matter. Thanks

James, PortSwigger Agent | Last updated: Oct 05, 2021 10:41AM UTC

Hi Ahmed, Thanks for getting in touch. I have responded to the same support request emailed in to us by your colleague Patrick.

Nate | Last updated: Nov 01, 2021 06:25PM UTC

Hello James, I am having the exact same issue. Would you mind posting the support response here for future use of any that might have this problem?

James, PortSwigger Agent | Last updated: Nov 02, 2021 10:43AM UTC

Hi Ahmed, The error message indicates that there are missing permissions to create the resources. We have seen this in some customer environments where they have Service Control Policies (SCPs) in place. To overcome this please add the "iam:CreateServiceLinkedRole" permission to the "burp-suite-enterprise-edition-CloudFormationServiceRole" role. Please let me know if you need detailed instructions on how to do this.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.