We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
GCP KMS/HSM doesn't support any (EC)DH algorithm, so as a workaround we're having to use envelope encryption with a Cloud KMS-backed symmetric key and the wrapped key stored in Datastore.
This means that the app has direct access to the ECDH private key and resulting shared key.
The option to have ECDH session keys stored in Cloud KMS/HSM.
The text was updated successfully, but these errors were encountered:
No branches or pull requests
Describe the problem
GCP KMS/HSM doesn't support any (EC)DH algorithm, so as a workaround we're having to use envelope encryption with a Cloud KMS-backed symmetric key and the wrapped key stored in Datastore.
This means that the app has direct access to the ECDH private key and resulting shared key.
Describe the solution you'd like
The option to have ECDH session keys stored in Cloud KMS/HSM.
See also
The text was updated successfully, but these errors were encountered: