Language

SqlColumnEncryptionKeyStoreProvider.SignColumnMasterKeyMetadataAsync Method

Definition

When implemented in a derived class, asynchronously signs the column master key metadata with the column master key referenced by the masterKeyPath parameter.

public virtual System.Threading.Tasks.Task<byte[]> SignColumnMasterKeyMetadataAsync(string masterKeyPath, bool allowEnclaveComputations, System.Threading.CancellationToken cancellationToken = default);
abstract member SignColumnMasterKeyMetadataAsync : string * bool * System.Threading.CancellationToken -> System.Threading.Tasks.Task<byte[]>
override this.SignColumnMasterKeyMetadataAsync : string * bool * System.Threading.CancellationToken -> System.Threading.Tasks.Task<byte[]>
Public Overridable Function SignColumnMasterKeyMetadataAsync (masterKeyPath As String, allowEnclaveComputations As Boolean, Optional cancellationToken As CancellationToken = Nothing) As Task(Of Byte())

Parameters

masterKeyPath
String

The column master key path. The path format is specific to the key store provider implementation (e.g. a thumbprint for the certificate store, or a key identifier URL for Azure Key Vault).

allowEnclaveComputations
Boolean

true to indicate that the column master key supports enclave computations; otherwise, false. When true, the generated signature covers the enclave-enabled property so that the metadata can later be verified for enclave use.

cancellationToken
CancellationToken

A token to cancel the asynchronous operation.

Returns

Task<Byte[]>

A task that, when completed, returns a Byte array representing the signature of the column master key metadata. The signature format is provider-specific.

Remarks

The default implementation first checks the cancellationToken and returns a canceled task if cancellation has been requested. Otherwise, it calls the synchronous SignColumnMasterKeyMetadata(String, Boolean) method, which throws a NotImplementedException by default. In this case, the returned task will be faulted with NotImplementedException rather than throwing synchronously.

Derived classes that perform I/O should override this method with a truly asynchronous implementation that honors the cancellation token.

Key store providers that wish to use enclaves with Always Encrypted should override this method with a truly asynchronous implementation when the signing operation involves I/O.

Applies to