-
Notifications
You must be signed in to change notification settings - Fork 1k
Open
Description
I'd like to be able to allow anyone to encrypt secrets to me; but only allow decryption through sops/KMS.
AWS support this with key_usage of ENCRYPT_DECRYPT. https://docs.aws.amazon.com/kms/latest/developerguide/symm-asymm-concepts.html#asymmetric-cmks
When I attempted to just use an RSA_4096 KMS key with sops I got:
Failed to call KMS encryption service: InvalidKeyUsageException: Algorithm SYMMETRIC_DEFAULT is incompatible with key spec RSA_4096.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels