Skip to content

Define behavior for a KMS-Keyring when given an generator which is an alias #49

@MatthewBennington

Description

@MatthewBennington

Presently the spec OnEncrypt section of the spec says that the keyring should use a "client that calls the AWS region specified in the generator ARN".

In cases where the keyring's generator is an alias (e.g. "alias/MyCryptoKey"), there is no way to determine the region to make call is.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions