Class GenerateDataKeyPairResponse

    • Method Detail

      • privateKeyCiphertextBlob

        public final SdkBytes privateKeyCiphertextBlob()

        The encrypted copy of the private key. When you use the HTTP API or the Amazon Web Services CLI, the value is Base64-encoded. Otherwise, it is not Base64-encoded.

        Returns:
        The encrypted copy of the private key. When you use the HTTP API or the Amazon Web Services CLI, the value is Base64-encoded. Otherwise, it is not Base64-encoded.
      • privateKeyPlaintext

        public final SdkBytes privateKeyPlaintext()

        The plaintext copy of the private key. When you use the HTTP API or the Amazon Web Services CLI, the value is Base64-encoded. Otherwise, it is not Base64-encoded.

        If the response includes the CiphertextForRecipient field, the PrivateKeyPlaintext field is null or empty.

        Returns:
        The plaintext copy of the private key. When you use the HTTP API or the Amazon Web Services CLI, the value is Base64-encoded. Otherwise, it is not Base64-encoded.

        If the response includes the CiphertextForRecipient field, the PrivateKeyPlaintext field is null or empty.

      • publicKey

        public final SdkBytes publicKey()

        The public key (in plaintext). When you use the HTTP API or the Amazon Web Services CLI, the value is Base64-encoded. Otherwise, it is not Base64-encoded.

        Returns:
        The public key (in plaintext). When you use the HTTP API or the Amazon Web Services CLI, the value is Base64-encoded. Otherwise, it is not Base64-encoded.
      • keyId

        public final String keyId()

        The Amazon Resource Name (key ARN) of the KMS key that encrypted the private key.

        Returns:
        The Amazon Resource Name (key ARN) of the KMS key that encrypted the private key.
      • keyPairSpecAsString

        public final String keyPairSpecAsString()

        The type of data key pair that was generated.

        If the service returns an enum value that is not available in the current SDK version, keyPairSpec will return DataKeyPairSpec.UNKNOWN_TO_SDK_VERSION. The raw value returned by the service is available from keyPairSpecAsString().

        Returns:
        The type of data key pair that was generated.
        See Also:
        DataKeyPairSpec
      • ciphertextForRecipient

        public final SdkBytes ciphertextForRecipient()

        The plaintext private data key encrypted with the public key from the attestation document. This ciphertext can be decrypted only by using a private key from the attested environment.

        This field is included in the response only when the Recipient parameter in the request includes a valid attestation document from an Amazon Web Services Nitro enclave or NitroTPM. For information about the interaction between KMS and Amazon Web Services Nitro Enclaves or Amazon Web Services NitroTPM, see Cryptographic attestation support in KMS in the Key Management Service Developer Guide.

        Returns:
        The plaintext private data key encrypted with the public key from the attestation document. This ciphertext can be decrypted only by using a private key from the attested environment.

        This field is included in the response only when the Recipient parameter in the request includes a valid attestation document from an Amazon Web Services Nitro enclave or NitroTPM. For information about the interaction between KMS and Amazon Web Services Nitro Enclaves or Amazon Web Services NitroTPM, see Cryptographic attestation support in KMS in the Key Management Service Developer Guide.

      • keyMaterialId

        public final String keyMaterialId()

        The identifier of the key material used to encrypt the private key.

        Returns:
        The identifier of the key material used to encrypt the private key.
      • toString

        public final String toString()
        Returns a string representation of this object. This is useful for testing and debugging. Sensitive data will be redacted from this string using a placeholder value.
        Overrides:
        toString in class Object