KmsClient
-objects.ciphertext
with associatedData
as associated authenticated data.plaintext
with associatedData
as associated authenticated data.KmsClient
registered with KmsClients.add(com.google.crypto.tink.KmsClient)
that supports keyUri
.Aead
backed by keyUri
.KmsClient
-objects that are needed by KeyManager
-objects for
primitives that use KMS-managed keys.AwsKmsClient.AwsKmsClient(java.lang.String)
with the Tink runtime.kmsKeyUri
starts with expectedPrefix
, and removes the prefix.modulusSize
is at least 2048-bit.publicExponent
is odd and greater than 65536.hash
is safe to use for digital signature.credentialPath
.