MCPcopy Create free account
hub / github.com/GoogleCloudPlatform/nodejs-docs-samples / main

Function main

kms/encryptAsymmetric.js:17–93  ·  view source on GitHub ↗
(
  projectId = 'my-project',
  locationId = 'us-east1',
  keyRingId = 'my-key-ring',
  keyId = 'my-key',
  versionId = '123',
  plaintextBuffer = Buffer.from('...')
)

Source from the content-addressed store, hash-verified

15'use strict';
16
17async function main(
18 projectId = 'my-project',
19 locationId = 'us-east1',
20 keyRingId = 'my-key-ring',
21 keyId = 'my-key',
22 versionId = '123',
23 plaintextBuffer = Buffer.from('...')
24) {
25 // [START kms_encrypt_asymmetric]
26 //
27 // TODO(developer): Uncomment these variables before running the sample.
28 //
29 // const projectId = 'my-project';
30 // const locationId = 'us-east1';
31 // const keyRingId = 'my-key-ring';
32 // const keyId = 'my-key';
33 // const versionId = '123';
34 // const plaintextBuffer = Buffer.from('...');
35
36 // Imports the Cloud KMS library
37 const {KeyManagementServiceClient} = require('@google-cloud/kms');
38
39 // Instantiates a client
40 const client = new KeyManagementServiceClient();
41
42 // Build the key version name
43 const versionName = client.cryptoKeyVersionPath(
44 projectId,
45 locationId,
46 keyRingId,
47 keyId,
48 versionId
49 );
50
51 async function encryptAsymmetric() {
52 // Get public key from Cloud KMS
53 const [publicKey] = await client.getPublicKey({
54 name: versionName,
55 });
56
57 // Optional, but recommended: perform integrity verification on publicKey.
58 // For more details on ensuring E2E in-transit integrity to and from Cloud KMS visit:
59 // https://cloud.google.com/kms/docs/data-integrity-guidelines
60 const crc32c = require('fast-crc32c');
61 if (publicKey.name !== versionName) {
62 throw new Error('GetPublicKey: request corrupted in-transit');
63 }
64 if (crc32c.calculate(publicKey.pem) !== Number(publicKey.pemCrc32c.value)) {
65 throw new Error('GetPublicKey: response corrupted in-transit');
66 }
67
68 // Import and setup crypto
69 const crypto = require('crypto');
70
71 // Encrypt plaintext locally using the public key. This example uses a key
72 // that was configured with sha256 hash with OAEP padding. Update these
73 // values to match the Cloud KMS key.
74 //

Callers 1

Calls 1

encryptAsymmetricFunction · 0.85

Tested by

no test coverage detected