Decrypting a Key Capsule
Function
This API is used to decrypt a key capsule.
Calling Method
For details, see Calling APIs.
Authorization Information
Each account has all the permissions required to call all APIs, but IAM users must be assigned the required permissions.
- If you are using role/policy-based authorization, see Permissions Policies and Supported Actions for details on the required permissions.
- If you are using identity policy-based authorization, the following identity policy-based permissions are required.
Action
Access Level
Resource Type (*: required)
Condition Key
Alias
Dependencies
kms:cmk:decryptDatakeyCapsule
Write
KeyId *
-
-
-
URI
POST /v1.0/{project_id}/kms/datakey-capsule/decrypt
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| project_id | Yes | String | Definition Project ID. For details, see Obtaining a Project ID. Constraints N/A Range The value returned by the IAM API is used, which contains 32 characters. Default Value N/A |
Request Parameters
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| X-Auth-Token | Yes | String | Definition User token. It can be obtained by calling the IAM API. The value of X-Subject-Token in the response header is the user token. Constraints N/A Range Obtain the value by calling the IAM API for obtaining the user token. Default Value N/A |
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| key_id | Yes | String | Definition Key ID Constraints The value is in UUID format and must match the regular expression ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$. Range N/A Default Value N/A |
| public_key | No | String | Definition Public key information, which is encrypted using the RSAES_OAEP_SHA_256 algorithm. If public_key is specified, KMS uses the public key to encrypt the plaintext DEK and returns the encrypted DEK. Constraints Only RSA public keys are supported. Range N/A Default Value N/A |
| datakey_capsule | Yes | String | Definition Key capsule Constraints N/A Range N/A Default Value N/A |
| attestation_document | Yes | attestation_document object | Definition Attestation document of the access point Constraints N/A Range N/A Default Value N/A |
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| ecs_signature | No | String | Definition ECS attestation document Constraints N/A Range N/A Default Value N/A |
| custom_signature | No | String | Definition Signature information of a general access point Constraints N/A Range N/A Default Value N/A |
| custom_public_key | No | String | Definition Public key information of a general access point Constraints The value is a Base64 string in the X509 public key format. Range N/A Default Value N/A |
| expire_time | No | String | Definition Expiration time of the general signature information Constraints The time is in ISO 8601 format: yyyy-mm-ddTHH:MM:SSZ. Range N/A Default Value N/A |
| service_token | No | String | Definition CCE access credential Constraints N/A Range N/A Default Value N/A |
Response Parameters
Status code: 200
| Parameter | Type | Description |
|---|---|---|
| key_id | String | Definition Key ID Range N/A |
| instance_id | String | Definition ID of the instance where the decryption capsule is located Range The value is the ECS ID, CCE cluster ID, or the value of access_point_id in common scenarios. |
| datakey | String | Definition Either datakey or datakey_cipher is returned. If public_key is not specified, datakey is returned. Range N/A |
| datakey_cipher | String | Definition Either datakey or datakey_cipher is returned. If public_key is specified, after datakey is encrypted using public_key, datakey_cipher is returned. Range N/A |
Example Requests
None
Example Responses
None
Status Codes
| Status Code | Description |
|---|---|
| 200 | Request succeeded. |
Error Codes
See Error Codes.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot