@Generated(value="software.amazon.awssdk:codegen") public final class GrantConstraints extends Object implements SdkPojo, Serializable, ToCopyableBuilder<GrantConstraints.Builder,GrantConstraints>
Use this structure to allow cryptographic operations in the grant only when the operation request includes the specified encryption context.
AWS KMS applies the grant constraints only to cryptographic operations that support an encryption context, that is, all cryptographic operations with a symmetric CMK. Grant constraints are not applied to operations that do not support an encryption context, such as cryptographic operations with asymmetric CMKs and management operations, such as DescribeKey or RetireGrant.
In a cryptographic operation, the encryption context in the decryption operation must be an exact, case-sensitive match for the keys and values in the encryption context of the encryption operation. Only the order of the pairs can vary.
However, in a grant constraint, the key in each key-value pair is not case sensitive, but the value is case sensitive.
To avoid confusion, do not use multiple encryption context pairs that differ only by case. To require a fully
case-sensitive encryption context, use the kms:EncryptionContext: and
kms:EncryptionContextKeys conditions in an IAM or key policy. For details, see kms:EncryptionContext: in the AWS Key Management Service Developer Guide .
| Modifier and Type | Class and Description |
|---|---|
static interface |
GrantConstraints.Builder |
| Modifier and Type | Method and Description |
|---|---|
static GrantConstraints.Builder |
builder() |
Map<String,String> |
encryptionContextEquals()
A list of key-value pairs that must match the encryption context in the cryptographic
operation request.
|
Map<String,String> |
encryptionContextSubset()
A list of key-value pairs that must be included in the encryption context of the cryptographic
operation request.
|
boolean |
equals(Object obj) |
boolean |
equalsBySdkFields(Object obj) |
<T> Optional<T> |
getValueForField(String fieldName,
Class<T> clazz) |
boolean |
hasEncryptionContextEquals()
Returns true if the EncryptionContextEquals property was specified by the sender (it may be empty), or false if
the sender did not specify the value (it will be empty).
|
boolean |
hasEncryptionContextSubset()
Returns true if the EncryptionContextSubset property was specified by the sender (it may be empty), or false if
the sender did not specify the value (it will be empty).
|
int |
hashCode() |
List<SdkField<?>> |
sdkFields() |
static Class<? extends GrantConstraints.Builder> |
serializableBuilderClass() |
GrantConstraints.Builder |
toBuilder() |
String |
toString()
Returns a string representation of this object.
|
clone, finalize, getClass, notify, notifyAll, wait, wait, waitcopypublic final boolean hasEncryptionContextSubset()
public final Map<String,String> encryptionContextSubset()
A list of key-value pairs that must be included in the encryption context of the cryptographic operation request. The grant allows the cryptographic operation only when the encryption context in the request includes the key-value pairs specified in this constraint, although it can include additional key-value pairs.
Attempts to modify the collection returned by this method will result in an UnsupportedOperationException.
You can use hasEncryptionContextSubset() to see if a value was sent in this field.
public final boolean hasEncryptionContextEquals()
public final Map<String,String> encryptionContextEquals()
A list of key-value pairs that must match the encryption context in the cryptographic operation request. The grant allows the operation only when the encryption context in the request is the same as the encryption context specified in this constraint.
Attempts to modify the collection returned by this method will result in an UnsupportedOperationException.
You can use hasEncryptionContextEquals() to see if a value was sent in this field.
public GrantConstraints.Builder toBuilder()
toBuilder in interface ToCopyableBuilder<GrantConstraints.Builder,GrantConstraints>public static GrantConstraints.Builder builder()
public static Class<? extends GrantConstraints.Builder> serializableBuilderClass()
public final boolean equalsBySdkFields(Object obj)
equalsBySdkFields in interface SdkPojopublic final String toString()
Copyright © 2021. All rights reserved.