MongoDB\Driver\ClientEncryption::createDataKey
PHP function
Edit on GitHub ✎
(mongodb >=1.7.0)
Creates a key document
Description
MongoDB\Driver\ClientEncryption::createDataKey(string $kmsProvider, array|null $options = null): MongoDB\BSON\Binary
Creates a new key document and inserts it into the key vault collection.
Parameters
kmsProviderThe KMS provider (e.g.
"local","aws") that will be used to encrypt the new data key.optionsOption Type Description masterKey arrayThe masterKey document identifies a KMS-specific key used to encrypt the new data key. This option is required unless kmsProvideris"local". MasterKey-options-by-providerkeyAltNames arrayAn optional list of string alternate names used to reference a key. If a key is created with alternate names, then encryption may refer to the key by the unique alternate name instead of by _id.keyMaterial MongoDB\BSON\BinaryAn optional 96-byte value to use as custom key material for the data key being created. If keyMaterial is given, the custom key material is used for encrypting and decrypting data. Otherwise, the key material for the new data key is generated from a cryptographically secure random device.
Return Values
Returns the identifier of the new key as a MongoDB\BSON\Binary object with subtype 4 (UUID).
Errors/Exceptions
- Throws
MongoDB\Driver\Exception\RuntimeExceptionon other errors.
Changelog
| Version | Description |
|---|---|
| PECL mongodb 1.20.0 | Added "delegated" to the KMIP provider masterKey options. |
| PECL mongodb 1.15.0 | Added the "keyMaterial" option. |
| PECL mongodb 1.10.0 | Azure and GCP are now supported as KMS providers for client-side encryption. |