diff -up /home/rfay/tmp/amazon/amazon.admin.inc ./amazon.admin.inc
--- /home/rfay/tmp/amazon/amazon.admin.inc	2008-06-28 12:12:14.000000000 -0600
+++ ./amazon.admin.inc	2009-06-12 21:27:00.000000000 -0600
@@ -41,9 +41,18 @@ function amazon_settings_form($form_stat
 
   $form['amazon_aws_access_key'] = array(
     '#type' => 'textfield',
-    '#title' => t('Amazon API key'),
-    '#description' => t('Applications must use a unique key to access Amazon services. One is supplied with the Drupal Amazon API module by default, but developers building high-traffic custom modules on the Amazon API may want to enter a custom key here.'),
-    '#default_value' => variable_get('amazon_aws_access_key', '0CD9RCQYM0TBVH55NB82'),
+    '#title' => t('Amazon AWS Access Key ID'),
+    '#description' => t('You must sign up for an Amazon AWS account to use the Product Advertising Service. This is a new requirement by Amazon (May, 2009). !more_info',array('!more_info'=>l(t('More information here.'),'http://docs.amazonwebservices.com/AWSECommerceService/latest/DG/index.html?AboutAWSAccounts.html',array('html'=>TRUE)))),
+    '#default_value' => variable_get('amazon_aws_access_key', ''),
+    '#required' => TRUE,
+  );
+
+  $form['amazon_aws_secret_access_key'] = array(
+    '#type' => 'textfield',
+    '#title' => t('Amazon AWS Secret Access Key'),
+    '#description' => t('You must sign up for an Amazon AWS account to use the Product Advertising Service. This is a new requirement by Amazon (May, 2009). !more_info',array('!more_info'=>l(t('More information here.'),'http://docs.amazonwebservices.com/AWSECommerceService/latest/DG/index.html?AboutAWSAccounts.html',array('html'=>TRUE)))),
+    '#default_value' => variable_get('amazon_aws_secret_access_key',""),
+    '#required' => TRUE,
   );
 
   // Now add the Javascript that does the fancy hide/show effects.
Common subdirectories: /home/rfay/tmp/amazon/amazon_filter and ./amazon_filter
diff -up /home/rfay/tmp/amazon/amazon.install ./amazon.install
--- /home/rfay/tmp/amazon/amazon.install	2008-06-25 22:21:40.000000000 -0600
+++ ./amazon.install	2009-06-12 21:26:24.000000000 -0600
@@ -5,6 +5,28 @@ function amazon_install() {
   drupal_install_schema('amazon');
 }
 
+/**
+ * implementation of hook_requirements to make sure we let them know about
+ * the requirement for amazon_aws_secret_access_key
+ * @param $phase
+ * @return unknown_type
+ */
+function amazon_requirements($phase) {
+  $secret_access_key=variable_get('amazon_aws_secret_access_key',"");
+  $api_key = variable_get('amazon_aws_access_key',"");
+  $requirement = array();
+  if (empty($secret_access_key) || empty($api_key)) {
+    drupal_set_message(t("The Amazon API must be configured with an Access Key ID and an Amazon AWS Secret Access Key to function. Go to !settings.",array("!settings"=>l(t("Amazon API Setttings"),'admin/settings/amazon'))));
+    $requirement['title'] = t("Amazon AWS Secret Access Key");
+    $requirement['severity'] = REQUIREMENT_WARNING;
+    $requirement['value'] = t("Not Set");
+    $requirement['description'] = t("The Amazon API must be configured with an Access Key ID and an Amazon AWS Secret Access Key to function. Go to !settings.",array("!settings"=>l(t("Amazon API Setttings"),'admin/settings/amazon')));
+    return array('amazon_aws_secret_access_key',$requirement);
+  }
+
+  return NULL;
+}
+
 function amazon_schema() {
   $schema['amazon_item'] = array(
     'fields' => array(
Common subdirectories: /home/rfay/tmp/amazon/amazon_media and ./amazon_media
diff -up /home/rfay/tmp/amazon/amazon.module ./amazon.module
--- /home/rfay/tmp/amazon/amazon.module	2008-09-12 17:22:20.000000000 -0600
+++ ./amazon.module	2009-06-12 21:04:00.000000000 -0600
@@ -9,7 +9,7 @@
  * save configuration and setup.
  */
 
-define('AMAZON_ECS_SCHEMA', '2008-04-07');
+define('AMAZON_ECS_SCHEMA', '2009-03-31');
 define('AMAZON_PARTICIPANT_TYPES', 'Author,Artist,Actor,Director,Creator');
 
 // Other common sizes include SwatchImage, TinyImage, and ThumbnailImage.
@@ -189,7 +189,7 @@ function amazon_http_request($operation,
   $parameters += array(
     'Service' => 'AWSECommerceService',
     'Version' => AMAZON_ECS_SCHEMA,
-    'AWSAccessKeyId' => variable_get('amazon_aws_access_key', '0CD9RCQYM0TBVH55NB82'),
+    'AWSAccessKeyId' => variable_get('amazon_aws_access_key', ''),
     'Operation' => $operation,
   );
   if ($associate_id = amazon_get_associate_id()) {
@@ -197,16 +197,39 @@ function amazon_http_request($operation,
       'AssociateTag' => $associate_id,
     );
   }
+  $parameters_after_hook = module_invoke_all('amazon_request', $parameters);
+  if (!empty($parameters_after_hook)) {
+    $parameters = $parameters_after_hook;
+  }
+  $parameters += array('Timestamp' => gmdate("Y-m-d\TH:i:s"). 'Z');
+  uksort($parameters, 'strnatcmp');
 
   $params = array();
   foreach($parameters as $key => $value) {
     if (is_array($value)) {
       $value = implode(',', $value);
     }
-    $params[] = urlencode($key) .'='. urlencode($value);
+    $param = str_replace("%7E", "~", rawurlencode($key));
+    $value = str_replace("%7E", "~", rawurlencode($value));
+    $params[] = $param .'='. $value;
+  }
+  $secret_access_key=variable_get('amazon_aws_secret_access_key',"");
+  if ($secret_access_key == "") {
+    watchdog('amazon',"No Secret Access Key configured. You must configure one at Admin->Settings->Amazon API",NULL,'error');
+    drupal_set_message(t("Amazon Module: No Secret Access Key is configured. Please contact your site administrator"));
+    return FALSE;
   }
-  module_invoke_all('amazon_request', $parameters);
-  $url = $locale_data['url'] .'?'. implode('&', $params);
+  // Thanks for signature creation code from http://mierendo.com/software/aws_signed_query/
+  $query_string = implode('&',$params);
+  $parsed_url = parse_url($locale_data['url']);
+  $host=strtolower($parsed_url['host']);
+  $string_to_sign="GET\n$host\n{$parsed_url['path']}\n$query_string";
+
+  $signature = base64_encode(hash_hmac('sha256', $string_to_sign, $secret_access_key, TRUE));
+  $signature = str_replace("%7E", "~", rawurlencode($signature));
+  $query_string .= "&Signature=$signature";
+
+  $url = $locale_data['url'] .'?'. $query_string;
   // Make the request and return a SimpleXML object.
   $results = drupal_http_request($url, array(), 'GET');
   if ($results->code == '200') {
