aws-cloudhsm-extractable-key-material-data-plane

An HSM user can export key material that was created or imported as extractable; access is governed by CloudHSM user credentials, not an AWS read API.

awscritical service: aws:cloudhsm emits ExposesCredential

Where it sits

locationCloudHSM client PKCS#11/JCE/OpenSSL key object with EXTRACTABLE=true
location kindsecret_value
data kindsprivate_key encryption_key_material signing_secret credential
emits edgeExposesCredential
serviceCloudHSM (aws:cloudhsm)

Collection recipe

access modedata_plane
operationPKCS#11 C_WrapKey / JCE key export
response pathprotocol key bytes or wrapped key bytes
encodingbinary
params{"ClusterId": "\u003ccluster-id\u003e", "KeyHandle": "\u003ckey-handle\u003e"}

References

move · open · esc close