Paul Kehrer | ca8e161 | 2015-03-16 20:57:09 -0500 | [diff] [blame] | 1 | .. hazmat:: |
| 2 | |
| 3 | .. module:: cryptography.hazmat.primitives.keywrap |
| 4 | |
| 5 | Key wrapping |
| 6 | ============ |
| 7 | |
| 8 | Key wrapping is a cryptographic construct that uses symmetric encryption to |
| 9 | encapsulate key material. |
| 10 | |
| 11 | .. function:: aes_key_wrap(wrapping_key, key_to_wrap, backend) |
| 12 | |
Paul Kehrer | 6f6cf00 | 2015-06-17 19:58:10 -0600 | [diff] [blame^] | 13 | .. versionadded:: 1.1 |
| 14 | |
Paul Kehrer | ca8e161 | 2015-03-16 20:57:09 -0500 | [diff] [blame] | 15 | :param bytes wrapping_key: The wrapping key. |
| 16 | |
| 17 | :param bytes key_to_wrap: The key to wrap. |
| 18 | |
| 19 | :param backend: A |
| 20 | :class:`~cryptography.hazmat.backends.interfaces.CipherBackend` |
| 21 | provider that supports |
| 22 | :class:`~cryptography.hazmat.primitives.ciphers.algorithms.AES`. |
| 23 | |
| 24 | :return bytes: The wrapped key as bytes. |
| 25 | |
| 26 | .. function:: aes_key_unwrap(wrapping_key, wrapped_key, backend) |
| 27 | |
Paul Kehrer | 6f6cf00 | 2015-06-17 19:58:10 -0600 | [diff] [blame^] | 28 | .. versionadded:: 1.1 |
| 29 | |
Paul Kehrer | ca8e161 | 2015-03-16 20:57:09 -0500 | [diff] [blame] | 30 | :param bytes wrapping_key: The wrapping key. |
| 31 | |
| 32 | :param bytes wrapped_key: The wrapped key. |
| 33 | |
| 34 | :param backend: A |
| 35 | :class:`~cryptography.hazmat.backends.interfaces.CipherBackend` |
| 36 | provider that supports |
| 37 | :class:`~cryptography.hazmat.primitives.ciphers.algorithms.AES`. |
| 38 | |
| 39 | :return bytes: The unwrapped key as bytes. |
| 40 | |
Paul Kehrer | 6f6cf00 | 2015-06-17 19:58:10 -0600 | [diff] [blame^] | 41 | :raises cryptography.hazmat.primitives.keywrap.InvalidUnwrap: This is |
| 42 | raised if the key is not successfully unwrapped. |
| 43 | |
Paul Kehrer | ca8e161 | 2015-03-16 20:57:09 -0500 | [diff] [blame] | 44 | Exceptions |
| 45 | ~~~~~~~~~~ |
| 46 | |
| 47 | .. class:: InvalidUnwrap |
| 48 | |
| 49 | This is raised when a wrapped key fails to unwrap. It can be caused by a |
| 50 | corrupted or invalid wrapped key or an invalid wrapping key. |