Skip to main content

decrypt_key_material

Function decrypt_key_material 

Source
pub async fn decrypt_key_material(ciphertext: Vec<u8>) -> Result<Vec<u8>>
Expand description

Recovers key material wrapped with an AWS KMS key by calling kms:Decrypt.

The ciphertext must have been produced by kms:Encrypt under a symmetric KMS key. The KMS key ID is embedded in the ciphertext blob, so it does not need to be supplied. The caller’s AWS identity requires the kms:Decrypt permission on that key, analogous to the policy documented on KmsSigner::new.

Note that unlike KmsSigner, where the private key never leaves KMS, the decrypted key material is returned to and held by the calling process.