class
Amazonite::Kms::GenerateDataKeyResponse
- Amazonite::Kms::GenerateDataKeyResponse
- Reference
- Object
Included Modules
- JSON::Serializable
Defined in:
kms/generate_data_key_response.crConstructors
- .new(pull : JSON::PullParser)
- .new(ciphertext_blob : Bytes | Nil = nil, plaintext : Bytes | Nil = nil, key_id : String | Nil = nil, ciphertext_for_recipient : Bytes | Nil = nil, key_material_id : String | Nil = nil)
- .new(*, __pull_for_json_serializable pull : JSON::PullParser)
Instance Method Summary
-
#==(other : self)
Returns
trueif this reference is the same as other. -
#ciphertext_blob : Bytes | Nil
The encrypted copy of the data key.
-
#ciphertext_blob=(ciphertext_blob : Bytes | Nil)
The encrypted copy of the data key.
-
#ciphertext_for_recipient : Bytes | Nil
The plaintext data key encrypted with the public key from the attestation document.
-
#ciphertext_for_recipient=(ciphertext_for_recipient : Bytes | Nil)
The plaintext data key encrypted with the public key from the attestation document.
-
#hash(hasher)
See
Object#hash(hasher) -
#key_id : String | Nil
The Amazon Resource Name (key ARN) of the KMS key that encrypted the data key.
-
#key_id=(key_id : String | Nil)
The Amazon Resource Name (key ARN) of the KMS key that encrypted the data key.
-
#key_material_id : String | Nil
The identifier of the key material used to encrypt the data key.
-
#key_material_id=(key_material_id : String | Nil)
The identifier of the key material used to encrypt the data key.
-
#plaintext : Bytes | Nil
The plaintext data key.
-
#plaintext=(plaintext : Bytes | Nil)
The plaintext data key.
- #validate! : Nil
Constructor Detail
Instance Method Detail
Returns true if this reference is the same as other. Invokes same?.
The encrypted copy of the data key. When you use the HTTP API or the Amazon Web Services CLI, the value is Base64-encoded. Otherwise, it is not Base64-encoded.
The encrypted copy of the data key. When you use the HTTP API or the Amazon Web Services CLI, the value is Base64-encoded. Otherwise, it is not Base64-encoded.
The plaintext data key encrypted with the public key from the attestation document. This ciphertext can be decrypted only by using a private key from the attested environment.
This field is included in the response only when the Recipient parameter in the request
includes a valid attestation document from an Amazon Web Services Nitro enclave or NitroTPM. For
information about the interaction between KMS and Amazon Web Services Nitro Enclaves or Amazon
Web Services NitroTPM, see Cryptographic attestation support in
KMS in
the Key Management Service Developer Guide.
The plaintext data key encrypted with the public key from the attestation document. This ciphertext can be decrypted only by using a private key from the attested environment.
This field is included in the response only when the Recipient parameter in the request
includes a valid attestation document from an Amazon Web Services Nitro enclave or NitroTPM. For
information about the interaction between KMS and Amazon Web Services Nitro Enclaves or Amazon
Web Services NitroTPM, see Cryptographic attestation support in
KMS in
the Key Management Service Developer Guide.
The Amazon Resource Name (key ARN) of the KMS key that encrypted the data key.
The Amazon Resource Name (key ARN) of the KMS key that encrypted the data key.
The identifier of the key material used to encrypt the data key. This field is omitted if the
request includes the Recipient parameter.
The identifier of the key material used to encrypt the data key. This field is omitted if the
request includes the Recipient parameter.
The plaintext data key. When you use the HTTP API or the Amazon Web Services CLI, the value is Base64-encoded. Otherwise, it is not Base64-encoded. Use this data key to encrypt your data outside of KMS. Then, remove it from memory as soon as possible.
If the response includes the CiphertextForRecipient field, the Plaintext field is null or
empty.
The plaintext data key. When you use the HTTP API or the Amazon Web Services CLI, the value is Base64-encoded. Otherwise, it is not Base64-encoded. Use this data key to encrypt your data outside of KMS. Then, remove it from memory as soon as possible.
If the response includes the CiphertextForRecipient field, the Plaintext field is null or
empty.