1 個回答
- 最新
- 最多得票
- 最多評論
2
In order to extract the cleartext key material for a private key two key attributes must be set by the key owner: EXTRACTABLE = true and WRAP_WITH_TRUSTED = false. Note that the key owner (CU who created the key) sets these values at creation and is the only one who can modify them. Users that the key has been shared with cannot change these attributes. Therefore only the CU who created (and therefore owns) the key can ensure that the material is not exported.
已回答 1 個月前
相關內容
- AWS 官方已更新 3 年前
- AWS 官方已更新 6 個月前
- AWS 官方已更新 3 年前
- AWS 官方已更新 2 年前