pub struct GenerateDataKeyWithoutPlaintextRequest {
pub encryption_context: Option<HashMap<String, String>>,
pub grant_tokens: Option<Vec<String>>,
pub key_id: String,
pub key_spec: Option<String>,
pub number_of_bytes: Option<i64>,
}
Fields§
§encryption_context: Option<HashMap<String, String>>
Specifies the encryption context that will be used when encrypting the data key.
An encryption context is a collection of non-secret key-value pairs that represents additional authenticated data. When you use an encryption context to encrypt data, you must specify the same (an exact case-sensitive match) encryption context to decrypt the data. An encryption context is optional when encrypting with a symmetric CMK, but it is highly recommended.
For more information, see Encryption Context in the AWS Key Management Service Developer Guide.
grant_tokens: Option<Vec<String>>
A list of grant tokens.
Use a grant token when your permission to call this operation comes from a new grant that has not yet achieved eventual consistency. For more information, see Grant token in the AWS Key Management Service Developer Guide.
key_id: String
The identifier of the symmetric customer master key (CMK) that encrypts the data key.
To specify a CMK, use its key ID, key ARN, alias name, or alias ARN. When using an alias name, prefix it with "alias/"
. To specify a CMK in a different AWS account, you must use the key ARN or alias ARN.
For example:
-
Key ID:
1234abcd-12ab-34cd-56ef-1234567890ab
-
Key ARN:
arn:aws:kms:us-east-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab
-
Alias name:
alias/ExampleAlias
-
Alias ARN:
arn:aws:kms:us-east-2:111122223333:alias/ExampleAlias
To get the key ID and key ARN for a CMK, use ListKeys or DescribeKey. To get the alias name and alias ARN, use ListAliases.
key_spec: Option<String>
The length of the data key. Use AES_128
to generate a 128-bit symmetric key, or AES_256
to generate a 256-bit symmetric key.
number_of_bytes: Option<i64>
The length of the data key in bytes. For example, use the value 64 to generate a 512-bit data key (64 bytes is 512 bits). For common key lengths (128-bit and 256-bit symmetric keys), we recommend that you use the KeySpec
field instead of this one.
Trait Implementations§
Source§impl Clone for GenerateDataKeyWithoutPlaintextRequest
impl Clone for GenerateDataKeyWithoutPlaintextRequest
Source§fn clone(&self) -> GenerateDataKeyWithoutPlaintextRequest
fn clone(&self) -> GenerateDataKeyWithoutPlaintextRequest
1.0.0 · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source
. Read moreSource§impl Default for GenerateDataKeyWithoutPlaintextRequest
impl Default for GenerateDataKeyWithoutPlaintextRequest
Source§fn default() -> GenerateDataKeyWithoutPlaintextRequest
fn default() -> GenerateDataKeyWithoutPlaintextRequest
Source§impl PartialEq for GenerateDataKeyWithoutPlaintextRequest
impl PartialEq for GenerateDataKeyWithoutPlaintextRequest
Source§fn eq(&self, other: &GenerateDataKeyWithoutPlaintextRequest) -> bool
fn eq(&self, other: &GenerateDataKeyWithoutPlaintextRequest) -> bool
self
and other
values to be equal, and is used by ==
.