sdkms.v1.apis.wrapping_and_unwrapping_api module

Fortanix DSM REST API

This is a set of REST APIs for accessing the Fortanix Data Security Manager. This includes APIs for managing accounts, and for performing cryptographic and key management operations.

OpenAPI spec version: 1.0.0-20200608 Contact: support@fortanix.com Generated by: https://github.com/swagger-api/swagger-codegen.git

Licensed under the Apache License, Version 2.0 (the “License”); you may not use this file except in compliance with the License. You may obtain a copy of the License at

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an “AS IS” BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

class sdkms.v1.apis.wrapping_and_unwrapping_api.WrappingAndUnwrappingApi(api_client=None)[source]

Bases: object

__init__(api_client=None)[source]
unwrap_key(key_id, body, async_call=False, **kwargs)[source]

Unwrap (decrypt) a wrapped key and import it into SDKMS. This allows securely importing into SDKMS security objects that were previously wrapped by SDKMS or another key management system. A new security object will be created in SDKMS with the unwrapped data. <br> The key-id parameter in the URL specifies the key that will be used to unwrap the other security object. This key must have the unwrapkey operation enabled. <br> The alg and mode parameters specify the encryption algorithm and cipher mode being used by the unwrapping key. The obj_type parameter specifies the object type of the security object being unwrapped. The size or elliptic curve of the object being unwrapped does not need to be specified.

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • key_id (str) – kid of security object (required)

  • body (UnwrapKeyRequest) – Unwrap key request (required)

Return type:

KeyObject

Returns:

If the method is called asynchronously, returns the request thread.

unwrap_key_ex(body, async_call=False, **kwargs)[source]

Unwrap (decrypt) a wrapped key and import it into SDKMS. This allows securely importing into SDKMS security objects that were previously wrapped by SDKMS or another key management system. A new security object will be created in SDKMS with the unwrapped data. <br> The key-id parameter in the URL specifies the key that will be used to unwrap the other security object. This key must have the unwrapkey operation enabled. <br> The alg and mode parameters specify the encryption algorithm and cipher mode being used by the unwrapping key. The obj_type parameter specifies the object type of the security object being unwrapped. The size or elliptic curve of the object being unwrapped does not need to be specified.

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • body (UnwrapKeyRequestEx) – Unwrap key request (required)

Return type:

KeyObject

Returns:

If the method is called asynchronously, returns the request thread.

wrap_key(key_id, body, async_call=False, **kwargs)[source]

Wrap (encrypt) an existing security object with a key. This allows keys to be securely exported from SDKMS so they can be later imported into SDKMS or another key management system. <br> The key-id parameter in the URL specifies the key that will be used to wrap the other security object. The security object being wrapped is specified inside of the request body. <br> The alg and mode parameters specify the encryption algorithm and cipher mode being used for the wrapping key. The algorithm of the key being wrapped is not provided to this API call. <br> The key being wrapped must have the export operation enabled. The wrapping key must have the wrapkey operation enabled. <br> The following wrapping operations are supported: * Symmetric keys, HMAC keys, opaque objects, and secret objects may be wrapped with symmetric or asymmetric keys. * Asymmetric keys may be wrapped with symmetric keys. Wrapping an asymmetric key with an asymmetric key is not supported. When wrapping with an asymmetric key, the wrapped object size must fit as plaintext for the wrapping key size and algorithm.

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • key_id (str) – kid of security object (required)

  • body (WrapKeyRequest) – Wrap key request (required)

Return type:

WrapKeyResponse

Returns:

If the method is called asynchronously, returns the request thread.

wrap_key_ex(body, async_call=False, **kwargs)[source]

Wrap (encrypt) an existing security object with a key. This allows keys to be securely exported from SDKMS so they can be later imported into SDKMS or another key management system. <br> The key-id parameter in the URL specifies the key that will be used to wrap the other security object. The security object being wrapped is specified inside of the request body. <br> The alg and mode parameters specify the encryption algorithm and cipher mode being used for the wrapping key. The algorithm of the key being wrapped is not provided to this API call. <br> The key being wrapped must have the export operation enabled. The wrapping key must have the wrapkey operation enabled. <br> The following wrapping operations are supported: * Symmetric keys, HMAC keys, opaque objects, and secret objects may be wrapped with symmetric or asymmetric keys. * Asymmetric keys may be wrapped with symmetric keys. Wrapping an asymmetric key with an asymmetric key is not supported. When wrapping with an asymmetric key, the wrapped object size must fit as plaintext for the wrapping key size and algorithm.

Parameters:
  • async_call (bool) – Whether the call should be performed asynchronously. (Default is False).

  • body (WrapKeyRequestEx) – Wrap key request (required)

Return type:

WrapKeyResponse

Returns:

If the method is called asynchronously, returns the request thread.