-
Notifications
You must be signed in to change notification settings - Fork 278
Opaque Key Encrypter/Decrypter #256
Comments
I don't think anyone is working on that at the momemt. |
To be clear: there is an opaque crypter interface, just not an implementation of that interface for KMS services. So it's possible to use KMS services already you just have to write the code yourself to hook it up. |
Can you link me to the source/documentation for this? I don't see anything like that in the source code. I want to be able to implement my own decrypter that will make an RPC to GCP KMS for a JWE. |
Oh, I see what you mean now. Using the Decrypter interface with my own implementation. I didn't know that this would work. Will give it a shot, thanks! |
Hmm, actually, I may have been mistaken, sorry. That will not work out of the box. I was thinking of the opaque wrappers we have but I just realized that's only for signing/verifying. But you want encryption/decryption, so you'd have to duplicate what's in opaque.go for encryption/decryption and update crypter.go to understand those. |
This was merged into v2 via #261, thanks for the help! |
Are there any plans to add an opaque key encrypter/decrypter to support use of AWS KMS/GCP KMS?
I can work on a PR for this, but I want to make sure that this is even warranted in the first place.
The text was updated successfully, but these errors were encountered: