Creating a Key Capsule
Function
This API is used to create a key capsule.
Calling Method
For details, see Calling APIs.
Authorization Information
Each account has all the permissions required to call all APIs, but IAM users must be assigned the required permissions.
- If you are using role/policy-based authorization, see Permissions Policies and Supported Actions for details on the required permissions.
- If you are using identity policy-based authorization, the following identity policy-based permissions are required.
Action
Access Level
Resource Type (*: required)
Condition Key
Alias
Dependencies
kms:cmk:createDatakeyCapsule
Write
KeyId *
-
-
-
URI
POST /v1.0/{project_id}/kms/datakey-capsule/create
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| project_id | Yes | String | Definition Project ID. For details, see Obtaining a Project ID. Constraints N/A Range The value returned by the IAM API is used, which contains 32 characters. Default Value N/A |
Request Parameters
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| X-Auth-Token | Yes | String | Definition User token. It can be obtained by calling the IAM API. The value of X-Subject-Token in the response header is the user token. Constraints N/A Range Obtain the value by calling the IAM API for obtaining the user token. Default Value N/A |
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| key_id | Yes | String | Definition Key ID Constraints The value is in UUID format and must match the regular expression ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$. Range N/A Default Value N/A |
| datakey_length | Yes | String | Definition Length of the DEK to be created Constraints The value can be 256 or 128. Range Default Value N/A |
| public_key | No | String | Definition Public key information, which is encrypted using the RSAES_OAEP_SHA_256 algorithm. If public_key is specified, KMS uses the public key to encrypt the plaintext DEK and returns the encrypted DEK. Constraints Only RSA public keys are supported. Range N/A Default Value N/A |
| policy_id | No | String | Definition Select either the key policy ID or inline key policy. Constraints Only RSA public keys are supported. Range N/A Default Value N/A |
| key_policy | No | String | Definition Select either the key policy ID or inline key policy. Constraints Only RSA public keys are supported. Range N/A Default Value N/A |
Response Parameters
Status code: 200
| Parameter | Type | Description |
|---|---|---|
| key_id | String | Definition Key ID Range N/A |
| datakey | String | Definition Either datakey or datakey_cipher is returned. If public_key is not specified, datakey is returned. Range N/A |
| datakey_cipher | String | Definition Either datakey or datakey_cipher is returned. If public_key is specified, after datakey is encrypted using public_key, datakey_cipher is returned. Range N/A |
| datakey_capsule | String | Definition Key capsule Range N/A |
Example Requests
None
Example Responses
None
Status Codes
| Status Code | Description |
|---|---|
| 200 | Request succeeded. |
Error Codes
See Error Codes.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot