1*e7b1675dSTing-Kang Chang // Copyright 2022 Google LLC 2*e7b1675dSTing-Kang Chang // 3*e7b1675dSTing-Kang Chang // Licensed under the Apache License, Version 2.0 (the "License"); 4*e7b1675dSTing-Kang Chang // you may not use this file except in compliance with the License. 5*e7b1675dSTing-Kang Chang // You may obtain a copy of the License at 6*e7b1675dSTing-Kang Chang // 7*e7b1675dSTing-Kang Chang // http://www.apache.org/licenses/LICENSE-2.0 8*e7b1675dSTing-Kang Chang // 9*e7b1675dSTing-Kang Chang // Unless required by applicable law or agreed to in writing, software 10*e7b1675dSTing-Kang Chang // distributed under the License is distributed on an "AS IS" BASIS, 11*e7b1675dSTing-Kang Chang // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 12*e7b1675dSTing-Kang Chang // See the License for the specific language governing permissions and 13*e7b1675dSTing-Kang Chang // limitations under the License. 14*e7b1675dSTing-Kang Chang // 15*e7b1675dSTing-Kang Chang /////////////////////////////////////////////////////////////////////////////// 16*e7b1675dSTing-Kang Chang 17*e7b1675dSTing-Kang Chang #include "walkthrough/write_keyset.h" 18*e7b1675dSTing-Kang Chang 19*e7b1675dSTing-Kang Chang // [START tink_walkthrough_write_keyset] 20*e7b1675dSTing-Kang Chang #include <fstream> 21*e7b1675dSTing-Kang Chang #include <memory> 22*e7b1675dSTing-Kang Chang #include <ostream> 23*e7b1675dSTing-Kang Chang #include <utility> 24*e7b1675dSTing-Kang Chang 25*e7b1675dSTing-Kang Chang #include "absl/status/status.h" 26*e7b1675dSTing-Kang Chang #include "absl/strings/string_view.h" 27*e7b1675dSTing-Kang Chang #include "tink/aead.h" 28*e7b1675dSTing-Kang Chang #include "tink/json_keyset_writer.h" 29*e7b1675dSTing-Kang Chang #include "tink/keyset_handle.h" 30*e7b1675dSTing-Kang Chang #include "tink/kms_client.h" 31*e7b1675dSTing-Kang Chang #include "tink/kms_clients.h" 32*e7b1675dSTing-Kang Chang 33*e7b1675dSTing-Kang Chang namespace tink_walkthrough { 34*e7b1675dSTing-Kang Chang 35*e7b1675dSTing-Kang Chang using ::crypto::tink::JsonKeysetWriter; 36*e7b1675dSTing-Kang Chang using ::crypto::tink::util::StatusOr; 37*e7b1675dSTing-Kang Chang 38*e7b1675dSTing-Kang Chang // Writes a `keyset` to `output_stream` in JSON format; the keyset is encrypted 39*e7b1675dSTing-Kang Chang // through a KMS service using the KMS key `master_kms_key_uri`. 40*e7b1675dSTing-Kang Chang // 41*e7b1675dSTing-Kang Chang // Prerequisites for this example: 42*e7b1675dSTing-Kang Chang // - Register AEAD implementations of Tink. 43*e7b1675dSTing-Kang Chang // - Register a KMS client that can use `master_kms_key_uri`. 44*e7b1675dSTing-Kang Chang // - Create a keyset and obtain a KeysetHandle to it. WriteEncryptedKeyset(const crypto::tink::KeysetHandle & keyset,std::unique_ptr<std::ostream> output_stream,absl::string_view master_kms_key_uri)45*e7b1675dSTing-Kang Changcrypto::tink::util::Status WriteEncryptedKeyset( 46*e7b1675dSTing-Kang Chang const crypto::tink::KeysetHandle& keyset, 47*e7b1675dSTing-Kang Chang std::unique_ptr<std::ostream> output_stream, 48*e7b1675dSTing-Kang Chang absl::string_view master_kms_key_uri) { 49*e7b1675dSTing-Kang Chang // Create a writer that will write the keyset to output_stream as JSON. 50*e7b1675dSTing-Kang Chang StatusOr<std::unique_ptr<JsonKeysetWriter>> writer = 51*e7b1675dSTing-Kang Chang JsonKeysetWriter::New(std::move(output_stream)); 52*e7b1675dSTing-Kang Chang if (!writer.ok()) return writer.status(); 53*e7b1675dSTing-Kang Chang // Get a KMS client for the given key URI. 54*e7b1675dSTing-Kang Chang StatusOr<const crypto::tink::KmsClient*> kms_client = 55*e7b1675dSTing-Kang Chang crypto::tink::KmsClients::Get(master_kms_key_uri); 56*e7b1675dSTing-Kang Chang if (!kms_client.ok()) return kms_client.status(); 57*e7b1675dSTing-Kang Chang // Get an Aead primitive that uses the KMS service to encrypt/decrypt. 58*e7b1675dSTing-Kang Chang StatusOr<std::unique_ptr<crypto::tink::Aead>> kms_aead = 59*e7b1675dSTing-Kang Chang (*kms_client)->GetAead(master_kms_key_uri); 60*e7b1675dSTing-Kang Chang if (!kms_aead.ok()) return kms_aead.status(); 61*e7b1675dSTing-Kang Chang return keyset.Write(writer->get(), **kms_aead); 62*e7b1675dSTing-Kang Chang } 63*e7b1675dSTing-Kang Chang 64*e7b1675dSTing-Kang Chang } // namespace tink_walkthrough 65*e7b1675dSTing-Kang Chang // [END tink_walkthrough_write_keyset] 66