sdkms.v1.apis.security_objects_api module
Fortanix DSM REST API
This is a set of REST APIs for accessing the Fortanix Data Security Manager. This includes APIs for managing accounts, and for performing cryptographic and key management operations.
OpenAPI spec version: 1.0.0-20200608 Contact: support@fortanix.com Generated by: https://github.com/swagger-api/swagger-codegen.git
Licensed under the Apache License, Version 2.0 (the “License”); you may not use this file except in compliance with the License. You may obtain a copy of the License at
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an “AS IS” BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
- class sdkms.v1.apis.security_objects_api.SecurityObjectsApi(api_client=None)[source]
Bases:
object- activate_security_object(key_id, async_call=False, **kwargs)[source]
Trigger the transition of a security object to Active state.
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
key_id (str) – kid of security object (required)
- Return type:
None
- Returns:
If the method is called asynchronously, returns the request thread.
- agree_key(body, async_call=False, **kwargs)[source]
This does a cryptographic key agreement operation between a public and private key. Both keys must have been generated from the same parameters (e.g. the same elliptic curve). Both keys must allow the AGREEKEY operation. The request body contains the requested properties for the new key as well as the mechanism (e.g. Diffie-Hellman) to be used to produce the key material for the new key. The output of this API should not be used directly as a cryptographic key. The target object type should be HMAC or Secret, and a key derivation procedure should be used to derive the actual key material.
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
body (AgreeKeyRequest) – Template of the agreed-upon security object (required)
- Return type:
KeyObject
- Returns:
If the method is called asynchronously, returns the request thread.
- delete_private_key(key_id, async_call=False, **kwargs)[source]
Removes the private portion of an asymmetric key from SDKMS. After this operation is performed, operations that require the private key, such as encryption and generating signatures, may no longer be performed.
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
key_id (str) – kid of security object (required)
- Return type:
None
- Returns:
If the method is called asynchronously, returns the request thread.
- delete_security_object(key_id, async_call=False, **kwargs)[source]
Delete a specified security object.
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
key_id (str) – kid of security object (required)
- Return type:
None
- Returns:
If the method is called asynchronously, returns the request thread.
- derive_key(key_id, body, async_call=False, **kwargs)[source]
This derives a key from an existing key and returns the properties of the new key. The request body contains the requested properties for the new as well as the mechanism to be used to produce the key material for the new key.
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
key_id (str) – kid of security object (required)
body (DeriveKeyRequest) – Name of security object (required)
- Return type:
KeyObject
- Returns:
If the method is called asynchronously, returns the request thread.
- derive_key_ex(body, async_call=False, **kwargs)[source]
This derives a key from an existing key and returns the properties of the new key. The request body contains the requested properties for the new as well as the mechanism to be used to produce the key material for the new key.
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
body (DeriveKeyRequestEx) – Name of security object (required)
- Return type:
KeyObject
- Returns:
If the method is called asynchronously, returns the request thread.
- destroy_security_object(key_id, async_call=False, **kwargs)[source]
Destroys a security object. Objects in the Destroyed state cannot be used in any cryptographic operation. Their metadata however, remains present.
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
key_id (str) – kid of security object (required)
- Return type:
None
- Returns:
If the method is called asynchronously, returns the request thread.
- export_sobject_components(body, async_call=False, **kwargs)[source]
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
body (ExportSobjectComponentsRequest) – Request to export a security object components (required)
- Return type:
ExportComponentsResponse
- Returns:
If the method is called asynchronously, returns the request thread.
- generate_security_object(body, async_call=False, **kwargs)[source]
Generate a new security object (such as an RSA key pair or an AES key) of the requested size or elliptic curve. <br> By default, all key operations except for Export that are implemented for that type of key will be enabled. These may be overridden by requesting specific operations in the key creation request. <br> Objects of type Opaque may not be generated with this API. They must be imported via the importSecurityObject API.
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
body (SobjectRequest) – Request to create, update, or import security object (required)
- Return type:
KeyObject
- Returns:
If the method is called asynchronously, returns the request thread.
- get_key_attestation(body, async_call=False, **kwargs)[source]
Retrieve key attestation statement for a security object.
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
body (KeyAttestationRequest) – Request to retrieve key attestation statement for a security object. (required)
- Return type:
KeyAttestationResponse
- Returns:
If the method is called asynchronously, returns the request thread.
- get_security_object(key_id, view=None, show_destroyed=None, show_deleted=None, async_call=False, **kwargs)[source]
Get the details of a particular security object.
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
key_id (str) – kid of security object (required)
view (str) – The encoding the value of an opaque object or certificate
show_destroyed (bool) – Whether security objects in the Destroyed state should be returned
show_deleted (bool) – Whether security objects in the Deleted state should be returned
- Return type:
KeyObject
- Returns:
If the method is called asynchronously, returns the request thread.
- get_security_object_digest(body, async_call=False, **kwargs)[source]
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
body (ObjectDigestRequest) – Object digest request (required)
- Return type:
DigestResponse
- Returns:
If the method is called asynchronously, returns the request thread.
- get_security_object_ex(body, view=None, show_destroyed=None, show_deleted=None, async_call=False, **kwargs)[source]
Get the details of a particular security object.
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
body (SobjectDescriptor) – Request to get a security object (required)
view (str) – The encoding the value of an opaque object or certificate
show_destroyed (bool) – Whether security objects in the Destroyed state should be returned
show_deleted (bool) – Whether security objects in the Deleted state should be returned
- Return type:
KeyObject
- Returns:
If the method is called asynchronously, returns the request thread.
- get_security_object_kcv(body, async_call=False, **kwargs)[source]
Get the key check value (KCV) of a symmetric key
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
body (SobjectDescriptor) – Request to export a security object (required)
- Return type:
KeyCheckValueResponse
- Returns:
If the method is called asynchronously, returns the request thread.
- get_security_object_value(key_id, async_call=False, **kwargs)[source]
Get the details and value of a particular exportable security object.
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
key_id (str) – kid of security object (required)
- Return type:
KeyObject
- Returns:
If the method is called asynchronously, returns the request thread.
- get_security_object_value_ex(body, async_call=False, **kwargs)[source]
Get the details and value of a particular exportable security object.
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
body (SobjectDescriptor) – Request to export a security object (required)
- Return type:
KeyObject
- Returns:
If the method is called asynchronously, returns the request thread.
- get_security_objects(name=None, group_id=None, creator=None, sort=None, compliant_with_policies=None, start=None, limit=None, offset=None, show_destroyed=None, show_deleted=None, async_call=False, **kwargs)[source]
Return detailed information about the security objects stored in Fortanix SDKMS.
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
name (str) – Only retrieve the security object with this name.
group_id (str) – Only retrieve security objects in the specified group.
creator (str) – Only retrieve security objects created by the user or application with the specified id.
sort (str) – This specifies the property (kid or name) and order (ascending or descending) with which to sort the security objects. By default, security objects are sorted by kid in ascending order. The syntax is “<property>:[asc|desc]” (e.g. “kid:desc”) or just “<property>” (ascending order by default).
compliant_with_policies (bool) – Whether this security object is compliant with cryptographic policies or not.
start (str) – If provided, this must be a value of the property specified in sort. Returned security objects will begin just above or just below this value (for asc/desc order resp.).
limit (int) – Maximum number of security objects to return. If not provided, the limit is 100.
offset (int) – Number of security objects past start to skip.
show_destroyed (bool) – Whether security objects in the Destroyed state should be returned
show_deleted (bool) – Whether security objects in the Deleted state should be returned
- Return type:
list[KeyObject]
- Returns:
If the method is called asynchronously, returns the request thread.
- import_security_object(body, async_call=False, **kwargs)[source]
Import a security object into SDKMS. <br> By default, all key operations except that are implemented for that type of key will be enabled. These may be overridden by requesting specific operations in the key import request. <br> For symmetric and asymmetric keys, value is base64-encoding of the key material in DER format.
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
body (SobjectRequest) – Request to create, update, or import security object (required)
- Return type:
KeyObject
- Returns:
If the method is called asynchronously, returns the request thread.
- import_sobject_components(body, async_call=False, **kwargs)[source]
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
body (ImportSobjectComponentsRequest) – Request to import a security object components (required)
- Return type:
KeyObject
- Returns:
If the method is called asynchronously, returns the request thread.
- persist_security_object(body, async_call=False, **kwargs)[source]
This API copies a transient key into a persisted security object in SDKMS. If the transient key’s origin is “FortanixHSM”, the origin of the persisted key will be “Transient”. If the transient key’s origin is “External”, the origin of the persisted key will be “External”.
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
body (PersistTransientKeyRequest) – Persist transient key request (required)
- Return type:
KeyObject
- Returns:
If the method is called asynchronously, returns the request thread.
- revert_history_item(key_id, body, async_call=False, **kwargs)[source]
When a Key Undo Policy is in place, security objects maintain a list of history items. Using this API endpoint, clients may revert the security object to a previous (non-expired) history item.
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
key_id (str) – kid of security object (required)
body (SobjectRequest) – Request to create, update, or import security object (required)
- Return type:
None
- Returns:
If the method is called asynchronously, returns the request thread.
- revoke_security_object(key_id, body, async_call=False, **kwargs)[source]
Trigger the transition of a security object to Deactivated or Compromised state depending on the RevocationReason Code.
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
key_id (str) – kid of security object (required)
body (RevocationReason) – Reason to revoke a security object (required)
- Return type:
None
- Returns:
If the method is called asynchronously, returns the request thread.
- rotate_security_object(body, async_call=False, **kwargs)[source]
Rotate an existing security object.
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
body (SobjectRequest) – Request to create, update, or import security object (required)
- Return type:
KeyObject
- Returns:
If the method is called asynchronously, returns the request thread.
- update_security_object(key_id, body, async_call=False, **kwargs)[source]
Update the properties of a security object.
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
key_id (str) – kid of security object (required)
body (SobjectRequest) – Request to create, update, or import security object (required)
- Return type:
KeyObject
- Returns:
If the method is called asynchronously, returns the request thread.
- verify_kcv(body, async_call=False, **kwargs)[source]
- Parameters:
async_call (bool) – Whether the call should be performed asynchronously. (Default is False).
body (VerifyKcvRequest) – Verify KCV request (required)
- Return type:
VerifyKcvResponse
- Returns:
If the method is called asynchronously, returns the request thread.