Class: Google::Apis::CloudkmsV1::CryptoKeyVersion

Inherits:
Object
  • Object
show all
Includes:
Google::Apis::Core::Hashable, Google::Apis::Core::JsonObjectSupport
Defined in:
lib/google/apis/cloudkms_v1/classes.rb,
lib/google/apis/cloudkms_v1/representations.rb,
lib/google/apis/cloudkms_v1/representations.rb

Overview

A CryptoKeyVersion represents an individual cryptographic key, and the associated key material. An ENABLED version can be used for cryptographic operations. For security reasons, the raw cryptographic key material represented by a CryptoKeyVersion can never be viewed or exported. It can only be used to encrypt, decrypt, or sign data when an authorized user or application invokes Cloud KMS.

Instance Attribute Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize(**args) ⇒ CryptoKeyVersion

Returns a new instance of CryptoKeyVersion.



980
981
982
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 980

def initialize(**args)
   update!(**args)
end

Instance Attribute Details

#algorithmString

Output only. The CryptoKeyVersionAlgorithm that this CryptoKeyVersion supports. Corresponds to the JSON property algorithm

Returns:

  • (String)


869
870
871
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 869

def algorithm
  @algorithm
end

#attestationGoogle::Apis::CloudkmsV1::KeyOperationAttestation

Contains an HSM-generated attestation about a key operation. For more information, see Verifying attestations. Corresponds to the JSON property attestation



876
877
878
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 876

def attestation
  @attestation
end

#create_timeString

Output only. The time at which this CryptoKeyVersion was created. Corresponds to the JSON property createTime

Returns:

  • (String)


881
882
883
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 881

def create_time
  @create_time
end

#destroy_event_timeString

Output only. The time this CryptoKeyVersion's key material was destroyed. Only present if state is DESTROYED. Corresponds to the JSON property destroyEventTime

Returns:

  • (String)


887
888
889
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 887

def destroy_event_time
  @destroy_event_time
end

#destroy_timeString

Output only. The time this CryptoKeyVersion's key material is scheduled for destruction. Only present if state is DESTROY_SCHEDULED. Corresponds to the JSON property destroyTime

Returns:

  • (String)


893
894
895
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 893

def destroy_time
  @destroy_time
end

#external_destruction_failure_reasonString

Output only. The root cause of the most recent external destruction failure. Only present if state is EXTERNAL_DESTRUCTION_FAILED. Corresponds to the JSON property externalDestructionFailureReason

Returns:

  • (String)


899
900
901
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 899

def external_destruction_failure_reason
  @external_destruction_failure_reason
end

#external_protection_level_optionsGoogle::Apis::CloudkmsV1::ExternalProtectionLevelOptions

ExternalProtectionLevelOptions stores a group of additional fields for configuring a CryptoKeyVersion that are specific to the EXTERNAL protection level and EXTERNAL_VPC protection levels. Corresponds to the JSON property externalProtectionLevelOptions



906
907
908
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 906

def external_protection_level_options
  @external_protection_level_options
end

#generate_timeString

Output only. The time this CryptoKeyVersion's key material was generated. Corresponds to the JSON property generateTime

Returns:

  • (String)


911
912
913
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 911

def generate_time
  @generate_time
end

#generation_failure_reasonString

Output only. The root cause of the most recent generation failure. Only present if state is GENERATION_FAILED. Corresponds to the JSON property generationFailureReason

Returns:

  • (String)


917
918
919
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 917

def generation_failure_reason
  @generation_failure_reason
end

#hsm_trustedBoolean Also known as: hsm_trusted?

Output only. Field indicating that the key wrapping key is trusted. This field is only valid for key purpose AES_256_WRAPPING, and protection level HSM_SINGLE_TENANT. Corresponds to the JSON property hsmTrusted

Returns:

  • (Boolean)


924
925
926
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 924

def hsm_trusted
  @hsm_trusted
end

#import_failure_reasonString

Output only. The root cause of the most recent import failure. Only present if state is IMPORT_FAILED. Corresponds to the JSON property importFailureReason

Returns:

  • (String)


931
932
933
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 931

def import_failure_reason
  @import_failure_reason
end

#import_jobString

Output only. The name of the ImportJob used in the most recent import of this CryptoKeyVersion. Only present if the underlying key material was imported. Corresponds to the JSON property importJob

Returns:

  • (String)


937
938
939
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 937

def import_job
  @import_job
end

#import_timeString

Output only. The time at which this CryptoKeyVersion's key material was most recently imported. Corresponds to the JSON property importTime

Returns:

  • (String)


943
944
945
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 943

def import_time
  @import_time
end

#nameString

Output only. The resource name for this CryptoKeyVersion in the format projects/*/locations/*/keyRings/*/cryptoKeys/*/cryptoKeyVersions/*. Corresponds to the JSON property name

Returns:

  • (String)


949
950
951
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 949

def name
  @name
end

#protection_levelString

Output only. The ProtectionLevel describing how crypto operations are performed with this CryptoKeyVersion. Corresponds to the JSON property protectionLevel

Returns:

  • (String)


955
956
957
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 955

def protection_level
  @protection_level
end

#reimport_eligibleBoolean Also known as: reimport_eligible?

Output only. Whether or not this key version is eligible for reimport, by being specified as a target in ImportCryptoKeyVersionRequest. crypto_key_version. Corresponds to the JSON property reimportEligible

Returns:

  • (Boolean)


962
963
964
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 962

def reimport_eligible
  @reimport_eligible
end

#stateString

The current state of the CryptoKeyVersion. Corresponds to the JSON property state

Returns:

  • (String)


968
969
970
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 968

def state
  @state
end

#trusted_wrapping_enabledBoolean Also known as: trusted_wrapping_enabled?

Immutable. Field indicating that the key may be wrapped by a trusted key. This field can be set for all key purposes except ENCRYPT_DECRYPT, and is only valid for keys with protection level HSM_SINGLE_TENANT. This field can only be set at creation or import time via CreateCryptoKeyVersion, or ImportCryptoKeyVersion. Corresponds to the JSON property trustedWrappingEnabled

Returns:

  • (Boolean)


977
978
979
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 977

def trusted_wrapping_enabled
  @trusted_wrapping_enabled
end

Instance Method Details

#update!(**args) ⇒ Object

Update properties of this object



985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
1001
1002
1003
1004
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 985

def update!(**args)
  @algorithm = args[:algorithm] if args.key?(:algorithm)
  @attestation = args[:attestation] if args.key?(:attestation)
  @create_time = args[:create_time] if args.key?(:create_time)
  @destroy_event_time = args[:destroy_event_time] if args.key?(:destroy_event_time)
  @destroy_time = args[:destroy_time] if args.key?(:destroy_time)
  @external_destruction_failure_reason = args[:external_destruction_failure_reason] if args.key?(:external_destruction_failure_reason)
  @external_protection_level_options = args[:external_protection_level_options] if args.key?(:external_protection_level_options)
  @generate_time = args[:generate_time] if args.key?(:generate_time)
  @generation_failure_reason = args[:generation_failure_reason] if args.key?(:generation_failure_reason)
  @hsm_trusted = args[:hsm_trusted] if args.key?(:hsm_trusted)
  @import_failure_reason = args[:import_failure_reason] if args.key?(:import_failure_reason)
  @import_job = args[:import_job] if args.key?(:import_job)
  @import_time = args[:import_time] if args.key?(:import_time)
  @name = args[:name] if args.key?(:name)
  @protection_level = args[:protection_level] if args.key?(:protection_level)
  @reimport_eligible = args[:reimport_eligible] if args.key?(:reimport_eligible)
  @state = args[:state] if args.key?(:state)
  @trusted_wrapping_enabled = args[:trusted_wrapping_enabled] if args.key?(:trusted_wrapping_enabled)
end