Interface EncapsulatedKeyManager
A manager for encapsulated keys.
EnvelopePropertyEncryptionProfile requires data keys to exist before they can be used for encryption. This
manager provides operations for creating and managing such keys.
When creating a key, the manager uses the configured BaseKeyEncapsulationService to generate and encapsulate
a new data key and registers the resulting EncapsulatedKeyRecord with the configured
BaseEncapsulatedKeyRecordRepository. Both synchronous and asynchronous implementations of these services
are supported.
- Since:
- 6.3.0
- See Also:
-
Method Summary
Modifier and TypeMethodDescriptiondefault EncapsulatedKeycreate()Creates a new encapsulated key without an alias.default EncapsulatedKeyCreates a new encapsulated key with the provided alias.create(String alias, KeyEncapsulationOptions encapsulationOptions) Creates a new encapsulated key with the provided alias andKeyEncapsulationOptions.default voidDeletes the alias from encapsulated key by id.voiddeleteById(String id) Deletes an encapsulated key by id.findByAlias(String alias) Finds an encapsulated key by its alias.voidsetAliasById(String id, String alias) Sets the alias of an encapsulated key by id.
-
Method Details
-
create
Creates a new encapsulated key without an alias.- Returns:
- the encapsulated key
-
create
Creates a new encapsulated key with the provided alias.- Parameters:
alias- the key alias, may be null- Returns:
- the encapsulated key
-
create
Creates a new encapsulated key with the provided alias andKeyEncapsulationOptions.- Parameters:
alias- the key alias, may be nullencapsulationOptions- the key encapsulation options, may be null- Returns:
- the encapsulated key
-
findByAlias
Finds an encapsulated key by its alias.- Parameters:
alias- the key alias, must not be null- Returns:
Optionalwith the encapsulated key orOptional.empty()when no key with the given alias has been found
-
setAliasById
Sets the alias of an encapsulated key by id. The alias must not be used by another key. To assign an alias currently used by another key, it must first be deleted from that key.- Parameters:
id- the key id, must not be nullalias- the new key alias, may be null to remove the alias
-
deleteAliasById
Deletes the alias from encapsulated key by id.- Parameters:
id- the key id, must not be null
-
deleteById
Deletes an encapsulated key by id.- Parameters:
id- the key id, must not be null
-