Language

SqlColumnEncryptionKeyStoreProvider.SignColumnMasterKeyMetadata Method

Definition

When implemented in a derived class, signs the column master key metadata with the column master key referenced by the masterKeyPath parameter.

public:
 virtual cli::array <System::Byte> ^ SignColumnMasterKeyMetadata(System::String ^ masterKeyPath, bool allowEnclaveComputations);
public virtual byte[] SignColumnMasterKeyMetadata(string masterKeyPath, bool allowEnclaveComputations);
abstract member SignColumnMasterKeyMetadata : string * bool -> byte[]
override this.SignColumnMasterKeyMetadata : string * bool -> byte[]
Public Overridable Function SignColumnMasterKeyMetadata (masterKeyPath As String, allowEnclaveComputations As Boolean) As Byte()

Parameters

masterKeyPath
String

The column master key path. The path format is specific to the key store provider implementation (e.g. a thumbprint for the certificate store, or a key identifier URL for Azure Key Vault).

allowEnclaveComputations
Boolean

true to indicate that the column master key supports enclave computations; otherwise, false. When true, the generated signature covers the enclave-enabled property so that the metadata can later be verified for enclave use.

Returns

Byte[]

Returns the signature of the column master key metadata. The format is provider-specific.

Exceptions

In all cases.

Remarks

To ensure that the SignColumnMasterKeyMetadata(String, Boolean) method doesn't break applications that rely on an old API, it throws a NotImplementedException exception by default.

The SignColumnMasterKeyMetadata(String, Boolean) method will be used by client tools that generate Column Master Keys (CMK) for customers. SignColumnMasterKeyMetadata(String, Boolean) must be implemented by the corresponding key store providers that wish to use enclaves with Always Encrypted.

Applies to