# Unable to generate key pair for EC2

**URL:** <https://community.cloudbank.org/t/unable-to-generate-key-pair-for-ec2/109>\
**Category:** AWS\
**Created:** [February 28, 2022, 9:42pm UTC](https://community.cloudbank.org/t/unable-to-generate-key-pair-for-ec2/109 "2022-02-28T21:42:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![rob](https://sea2.discourse-cdn.com/flex016/user_avatar/community.cloudbank.org/rob/32/5_2.png) [@rob](https://community.cloudbank.org/u/rob)\
**Post date:** [February 28, 2022, 9:42pm UTC](https://community.cloudbank.org/t/unable-to-generate-key-pair-for-ec2/109/1 "2022-02-28T21:42:46Z")

</div>

As an IAM User I have run into a problem connecting to an EC2 instance on AWS. On the AWS console under EC2 \> Network & Security \> Key Pairs: I select **Create Key Pair** , provide a key pair name, select ‘RSA’, select ‘.pem’ file format, click the **Create** button. I get: _You are not authorized to perform this operation._

---

<div class="post-metadata">

**Author:** ![rob](https://sea2.discourse-cdn.com/flex016/user_avatar/community.cloudbank.org/rob/32/5_2.png) [@rob](https://community.cloudbank.org/u/rob)\
**Post date:** [February 28, 2022, 9:46pm UTC](https://community.cloudbank.org/t/unable-to-generate-key-pair-for-ec2/109/2 "2022-02-28T21:46:36Z")

</div>

Your steps look correct; so let’s try giving your IAM User specific permission to do EC2 “everything”. You may be able to do this while logged in on your IAM account; but certainly you can do it from the admin account if necessary. (An ‘admin’ is what you set up the first time you log in as root. The idea is that admin has authority to do this sort of thing but without being root.)

In the AWS Console go to IAM \> Users, click on your User name \> dedicated page with multiple tabs. The left-most tab is Permissions.

Click on Add Permissions and notice three boxes at the top. Click Attach Existing Policies Directly. Search for AmazonEC2FullAccess. Tick the little box and then click Next: Review \> Click Add Permissions. This should give you the necessary permission to create and use key pairs.
