Skip to main content

aws_sdk_kms/operation/verify/
_verify_input.rs

1// Code generated by software.amazon.smithy.rust.codegen.smithy-rs. DO NOT EDIT.
2#[allow(missing_docs)] // documentation missing in model
3#[non_exhaustive]
4#[derive(::std::clone::Clone, ::std::cmp::PartialEq)]
5pub struct VerifyInput {
6    /// <p>Identifies the asymmetric KMS key that will be used to verify the signature. This must be the same KMS key that was used to generate the signature. If you specify a different KMS key, the signature verification fails.</p>
7    /// <p>To specify a KMS key, use its key ID, key ARN, alias name, or alias ARN. When using an alias name, prefix it with <code>"alias/"</code>. To specify a KMS key in a different Amazon Web Services account, you must use the key ARN or alias ARN.</p>
8    /// <p>For example:</p>
9    /// <ul>
10    /// <li>
11    /// <p>Key ID: <code>1234abcd-12ab-34cd-56ef-1234567890ab</code></p></li>
12    /// <li>
13    /// <p>Key ARN: <code>arn:aws:kms:us-east-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab</code></p></li>
14    /// <li>
15    /// <p>Alias name: <code>alias/ExampleAlias</code></p></li>
16    /// <li>
17    /// <p>Alias ARN: <code>arn:aws:kms:us-east-2:111122223333:alias/ExampleAlias</code></p></li>
18    /// </ul>
19    /// <p>To get the key ID and key ARN for a KMS key, use <code>ListKeys</code> or <code>DescribeKey</code>. To get the alias name and alias ARN, use <code>ListAliases</code>.</p>
20    pub key_id: ::std::option::Option<::std::string::String>,
21    /// <p>Specifies the message that was signed. You can submit a raw message of up to 4096 bytes, or a hash digest of the message. If you submit a digest, use the <code>MessageType</code> parameter with a value of <code>DIGEST</code>.</p>
22    /// <p>If the message specified here is different from the message that was signed, the signature verification fails. A message and its hash digest are considered to be the same message.</p>
23    pub message: ::std::option::Option<::aws_smithy_types::Blob>,
24    /// <p>Tells KMS whether the value of the <code>Message</code> parameter should be hashed as part of the signing algorithm. Use <code>RAW</code> for unhashed messages; use <code>DIGEST</code> for message digests, which are already hashed; use <code>EXTERNAL_MU</code> for 64-byte representative μ used in ML-DSA signing as defined in NIST FIPS 204 Section 6.2.</p>
25    /// <p>When the value of <code>MessageType</code> is <code>RAW</code>, KMS uses the standard signing algorithm, which begins with a hash function. When the value is <code>DIGEST</code>, KMS skips the hashing step in the signing algorithm. When the value is <code>EXTERNAL_MU</code> KMS skips the concatenated hashing of the public key hash and the message done in the ML-DSA signing algorithm.</p><important>
26    /// <p>Use the <code>DIGEST</code> or <code>EXTERNAL_MU</code> value only when the value of the <code>Message</code> parameter is a message digest. If you use the <code>DIGEST</code> value with an unhashed message, the security of the signing operation can be compromised.</p>
27    /// </important>
28    /// <p>When using ECC_NIST_EDWARDS25519 KMS keys:</p>
29    /// <ul>
30    /// <li>
31    /// <p>ED25519_SHA_512 signing algorithm requires KMS <code>MessageType:RAW</code></p></li>
32    /// <li>
33    /// <p>ED25519_PH_SHA_512 signing algorithm requires KMS <code>MessageType:DIGEST</code></p></li>
34    /// </ul><important>
35    /// <p>When you specify the ED25519_PH_SHA_512 signing algorithm with <code>MessageType:DIGEST</code>, KMS still performs the SHA-512 prehash described in <a href="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf#page=39">Step 1 of Section 7.8.1 in FIPS 186-5</a>. This means the input is hashed twice: once by you and once by KMS.</p>
36    /// </important>
37    /// <p>When the value of <code>MessageType</code> is <code>DIGEST</code>, the length of the <code>Message</code> value must match the length of hashed messages for the specified signing algorithm.</p>
38    /// <p>When the value of <code>MessageType</code> is <code>EXTERNAL_MU</code> the length of the <code>Message</code> value must be 64 bytes.</p>
39    /// <p>You can submit a message digest and omit the <code>MessageType</code> or specify <code>RAW</code> so the digest is hashed again while signing. However, if the signed message is hashed once while signing, but twice while verifying, verification fails, even when the message hasn't changed.</p>
40    /// <p>The hashing algorithm that <code>Verify</code> uses is based on the <code>SigningAlgorithm</code> value.</p>
41    /// <ul>
42    /// <li>
43    /// <p>Signing algorithms that end in SHA_256 use the SHA_256 hashing algorithm.</p></li>
44    /// <li>
45    /// <p>Signing algorithms that end in SHA_384 use the SHA_384 hashing algorithm.</p></li>
46    /// <li>
47    /// <p>Signing algorithms that end in SHA_512 use the SHA_512 hashing algorithm.</p></li>
48    /// <li>
49    /// <p>Signing algorithms that end in SHAKE_256 use the SHAKE_256 hashing algorithm.</p></li>
50    /// <li>
51    /// <p>SM2DSA uses the SM3 hashing algorithm. For details, see <a href="https://docs.aws.amazon.com/kms/latest/developerguide/offline-operations.html#key-spec-sm-offline-verification">Offline verification with SM2 key pairs</a>.</p></li>
52    /// </ul>
53    pub message_type: ::std::option::Option<crate::types::MessageType>,
54    /// <p>The signature that the <code>Sign</code> operation generated.</p>
55    pub signature: ::std::option::Option<::aws_smithy_types::Blob>,
56    /// <p>The signing algorithm that was used to sign the message. If you submit a different algorithm, the signature verification fails.</p>
57    pub signing_algorithm: ::std::option::Option<crate::types::SigningAlgorithmSpec>,
58    /// <p>A list of grant tokens.</p>
59    /// <p>Use a grant token when your permission to call this operation comes from a new grant that has not yet achieved <i>eventual consistency</i>. For more information, see <a href="https://docs.aws.amazon.com/kms/latest/developerguide/grants.html#grant_token">Grant token</a> and <a href="https://docs.aws.amazon.com/kms/latest/developerguide/using-grant-token.html">Using a grant token</a> in the <i>Key Management Service Developer Guide</i>.</p>
60    pub grant_tokens: ::std::option::Option<::std::vec::Vec<::std::string::String>>,
61    /// <p>Checks if your request will succeed. <code>DryRun</code> is an optional parameter.</p>
62    /// <p>To learn more about how to use this parameter, see <a href="https://docs.aws.amazon.com/kms/latest/developerguide/testing-permissions.html">Testing your permissions</a> in the <i>Key Management Service Developer Guide</i>.</p>
63    pub dry_run: ::std::option::Option<bool>,
64}
65impl VerifyInput {
66    /// <p>Identifies the asymmetric KMS key that will be used to verify the signature. This must be the same KMS key that was used to generate the signature. If you specify a different KMS key, the signature verification fails.</p>
67    /// <p>To specify a KMS key, use its key ID, key ARN, alias name, or alias ARN. When using an alias name, prefix it with <code>"alias/"</code>. To specify a KMS key in a different Amazon Web Services account, you must use the key ARN or alias ARN.</p>
68    /// <p>For example:</p>
69    /// <ul>
70    /// <li>
71    /// <p>Key ID: <code>1234abcd-12ab-34cd-56ef-1234567890ab</code></p></li>
72    /// <li>
73    /// <p>Key ARN: <code>arn:aws:kms:us-east-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab</code></p></li>
74    /// <li>
75    /// <p>Alias name: <code>alias/ExampleAlias</code></p></li>
76    /// <li>
77    /// <p>Alias ARN: <code>arn:aws:kms:us-east-2:111122223333:alias/ExampleAlias</code></p></li>
78    /// </ul>
79    /// <p>To get the key ID and key ARN for a KMS key, use <code>ListKeys</code> or <code>DescribeKey</code>. To get the alias name and alias ARN, use <code>ListAliases</code>.</p>
80    pub fn key_id(&self) -> ::std::option::Option<&str> {
81        self.key_id.as_deref()
82    }
83    /// <p>Specifies the message that was signed. You can submit a raw message of up to 4096 bytes, or a hash digest of the message. If you submit a digest, use the <code>MessageType</code> parameter with a value of <code>DIGEST</code>.</p>
84    /// <p>If the message specified here is different from the message that was signed, the signature verification fails. A message and its hash digest are considered to be the same message.</p>
85    pub fn message(&self) -> ::std::option::Option<&::aws_smithy_types::Blob> {
86        self.message.as_ref()
87    }
88    /// <p>Tells KMS whether the value of the <code>Message</code> parameter should be hashed as part of the signing algorithm. Use <code>RAW</code> for unhashed messages; use <code>DIGEST</code> for message digests, which are already hashed; use <code>EXTERNAL_MU</code> for 64-byte representative μ used in ML-DSA signing as defined in NIST FIPS 204 Section 6.2.</p>
89    /// <p>When the value of <code>MessageType</code> is <code>RAW</code>, KMS uses the standard signing algorithm, which begins with a hash function. When the value is <code>DIGEST</code>, KMS skips the hashing step in the signing algorithm. When the value is <code>EXTERNAL_MU</code> KMS skips the concatenated hashing of the public key hash and the message done in the ML-DSA signing algorithm.</p><important>
90    /// <p>Use the <code>DIGEST</code> or <code>EXTERNAL_MU</code> value only when the value of the <code>Message</code> parameter is a message digest. If you use the <code>DIGEST</code> value with an unhashed message, the security of the signing operation can be compromised.</p>
91    /// </important>
92    /// <p>When using ECC_NIST_EDWARDS25519 KMS keys:</p>
93    /// <ul>
94    /// <li>
95    /// <p>ED25519_SHA_512 signing algorithm requires KMS <code>MessageType:RAW</code></p></li>
96    /// <li>
97    /// <p>ED25519_PH_SHA_512 signing algorithm requires KMS <code>MessageType:DIGEST</code></p></li>
98    /// </ul><important>
99    /// <p>When you specify the ED25519_PH_SHA_512 signing algorithm with <code>MessageType:DIGEST</code>, KMS still performs the SHA-512 prehash described in <a href="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf#page=39">Step 1 of Section 7.8.1 in FIPS 186-5</a>. This means the input is hashed twice: once by you and once by KMS.</p>
100    /// </important>
101    /// <p>When the value of <code>MessageType</code> is <code>DIGEST</code>, the length of the <code>Message</code> value must match the length of hashed messages for the specified signing algorithm.</p>
102    /// <p>When the value of <code>MessageType</code> is <code>EXTERNAL_MU</code> the length of the <code>Message</code> value must be 64 bytes.</p>
103    /// <p>You can submit a message digest and omit the <code>MessageType</code> or specify <code>RAW</code> so the digest is hashed again while signing. However, if the signed message is hashed once while signing, but twice while verifying, verification fails, even when the message hasn't changed.</p>
104    /// <p>The hashing algorithm that <code>Verify</code> uses is based on the <code>SigningAlgorithm</code> value.</p>
105    /// <ul>
106    /// <li>
107    /// <p>Signing algorithms that end in SHA_256 use the SHA_256 hashing algorithm.</p></li>
108    /// <li>
109    /// <p>Signing algorithms that end in SHA_384 use the SHA_384 hashing algorithm.</p></li>
110    /// <li>
111    /// <p>Signing algorithms that end in SHA_512 use the SHA_512 hashing algorithm.</p></li>
112    /// <li>
113    /// <p>Signing algorithms that end in SHAKE_256 use the SHAKE_256 hashing algorithm.</p></li>
114    /// <li>
115    /// <p>SM2DSA uses the SM3 hashing algorithm. For details, see <a href="https://docs.aws.amazon.com/kms/latest/developerguide/offline-operations.html#key-spec-sm-offline-verification">Offline verification with SM2 key pairs</a>.</p></li>
116    /// </ul>
117    pub fn message_type(&self) -> ::std::option::Option<&crate::types::MessageType> {
118        self.message_type.as_ref()
119    }
120    /// <p>The signature that the <code>Sign</code> operation generated.</p>
121    pub fn signature(&self) -> ::std::option::Option<&::aws_smithy_types::Blob> {
122        self.signature.as_ref()
123    }
124    /// <p>The signing algorithm that was used to sign the message. If you submit a different algorithm, the signature verification fails.</p>
125    pub fn signing_algorithm(&self) -> ::std::option::Option<&crate::types::SigningAlgorithmSpec> {
126        self.signing_algorithm.as_ref()
127    }
128    /// <p>A list of grant tokens.</p>
129    /// <p>Use a grant token when your permission to call this operation comes from a new grant that has not yet achieved <i>eventual consistency</i>. For more information, see <a href="https://docs.aws.amazon.com/kms/latest/developerguide/grants.html#grant_token">Grant token</a> and <a href="https://docs.aws.amazon.com/kms/latest/developerguide/using-grant-token.html">Using a grant token</a> in the <i>Key Management Service Developer Guide</i>.</p>
130    ///
131    /// If no value was sent for this field, a default will be set. If you want to determine if no value was sent, use `.grant_tokens.is_none()`.
132    pub fn grant_tokens(&self) -> &[::std::string::String] {
133        self.grant_tokens.as_deref().unwrap_or_default()
134    }
135    /// <p>Checks if your request will succeed. <code>DryRun</code> is an optional parameter.</p>
136    /// <p>To learn more about how to use this parameter, see <a href="https://docs.aws.amazon.com/kms/latest/developerguide/testing-permissions.html">Testing your permissions</a> in the <i>Key Management Service Developer Guide</i>.</p>
137    pub fn dry_run(&self) -> ::std::option::Option<bool> {
138        self.dry_run
139    }
140}
141impl ::std::fmt::Debug for VerifyInput {
142    fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
143        let mut formatter = f.debug_struct("VerifyInput");
144        formatter.field("key_id", &self.key_id);
145        formatter.field("message", &"*** Sensitive Data Redacted ***");
146        formatter.field("message_type", &self.message_type);
147        formatter.field("signature", &self.signature);
148        formatter.field("signing_algorithm", &self.signing_algorithm);
149        formatter.field("grant_tokens", &self.grant_tokens);
150        formatter.field("dry_run", &self.dry_run);
151        formatter.finish()
152    }
153}
154impl VerifyInput {
155    /// Creates a new builder-style object to manufacture [`VerifyInput`](crate::operation::verify::VerifyInput).
156    pub fn builder() -> crate::operation::verify::builders::VerifyInputBuilder {
157        crate::operation::verify::builders::VerifyInputBuilder::default()
158    }
159}
160
161/// A builder for [`VerifyInput`](crate::operation::verify::VerifyInput).
162#[derive(::std::clone::Clone, ::std::cmp::PartialEq, ::std::default::Default)]
163#[non_exhaustive]
164pub struct VerifyInputBuilder {
165    pub(crate) key_id: ::std::option::Option<::std::string::String>,
166    pub(crate) message: ::std::option::Option<::aws_smithy_types::Blob>,
167    pub(crate) message_type: ::std::option::Option<crate::types::MessageType>,
168    pub(crate) signature: ::std::option::Option<::aws_smithy_types::Blob>,
169    pub(crate) signing_algorithm: ::std::option::Option<crate::types::SigningAlgorithmSpec>,
170    pub(crate) grant_tokens: ::std::option::Option<::std::vec::Vec<::std::string::String>>,
171    pub(crate) dry_run: ::std::option::Option<bool>,
172}
173impl VerifyInputBuilder {
174    /// <p>Identifies the asymmetric KMS key that will be used to verify the signature. This must be the same KMS key that was used to generate the signature. If you specify a different KMS key, the signature verification fails.</p>
175    /// <p>To specify a KMS key, use its key ID, key ARN, alias name, or alias ARN. When using an alias name, prefix it with <code>"alias/"</code>. To specify a KMS key in a different Amazon Web Services account, you must use the key ARN or alias ARN.</p>
176    /// <p>For example:</p>
177    /// <ul>
178    /// <li>
179    /// <p>Key ID: <code>1234abcd-12ab-34cd-56ef-1234567890ab</code></p></li>
180    /// <li>
181    /// <p>Key ARN: <code>arn:aws:kms:us-east-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab</code></p></li>
182    /// <li>
183    /// <p>Alias name: <code>alias/ExampleAlias</code></p></li>
184    /// <li>
185    /// <p>Alias ARN: <code>arn:aws:kms:us-east-2:111122223333:alias/ExampleAlias</code></p></li>
186    /// </ul>
187    /// <p>To get the key ID and key ARN for a KMS key, use <code>ListKeys</code> or <code>DescribeKey</code>. To get the alias name and alias ARN, use <code>ListAliases</code>.</p>
188    /// This field is required.
189    pub fn key_id(mut self, input: impl ::std::convert::Into<::std::string::String>) -> Self {
190        self.key_id = ::std::option::Option::Some(input.into());
191        self
192    }
193    /// <p>Identifies the asymmetric KMS key that will be used to verify the signature. This must be the same KMS key that was used to generate the signature. If you specify a different KMS key, the signature verification fails.</p>
194    /// <p>To specify a KMS key, use its key ID, key ARN, alias name, or alias ARN. When using an alias name, prefix it with <code>"alias/"</code>. To specify a KMS key in a different Amazon Web Services account, you must use the key ARN or alias ARN.</p>
195    /// <p>For example:</p>
196    /// <ul>
197    /// <li>
198    /// <p>Key ID: <code>1234abcd-12ab-34cd-56ef-1234567890ab</code></p></li>
199    /// <li>
200    /// <p>Key ARN: <code>arn:aws:kms:us-east-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab</code></p></li>
201    /// <li>
202    /// <p>Alias name: <code>alias/ExampleAlias</code></p></li>
203    /// <li>
204    /// <p>Alias ARN: <code>arn:aws:kms:us-east-2:111122223333:alias/ExampleAlias</code></p></li>
205    /// </ul>
206    /// <p>To get the key ID and key ARN for a KMS key, use <code>ListKeys</code> or <code>DescribeKey</code>. To get the alias name and alias ARN, use <code>ListAliases</code>.</p>
207    pub fn set_key_id(mut self, input: ::std::option::Option<::std::string::String>) -> Self {
208        self.key_id = input;
209        self
210    }
211    /// <p>Identifies the asymmetric KMS key that will be used to verify the signature. This must be the same KMS key that was used to generate the signature. If you specify a different KMS key, the signature verification fails.</p>
212    /// <p>To specify a KMS key, use its key ID, key ARN, alias name, or alias ARN. When using an alias name, prefix it with <code>"alias/"</code>. To specify a KMS key in a different Amazon Web Services account, you must use the key ARN or alias ARN.</p>
213    /// <p>For example:</p>
214    /// <ul>
215    /// <li>
216    /// <p>Key ID: <code>1234abcd-12ab-34cd-56ef-1234567890ab</code></p></li>
217    /// <li>
218    /// <p>Key ARN: <code>arn:aws:kms:us-east-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab</code></p></li>
219    /// <li>
220    /// <p>Alias name: <code>alias/ExampleAlias</code></p></li>
221    /// <li>
222    /// <p>Alias ARN: <code>arn:aws:kms:us-east-2:111122223333:alias/ExampleAlias</code></p></li>
223    /// </ul>
224    /// <p>To get the key ID and key ARN for a KMS key, use <code>ListKeys</code> or <code>DescribeKey</code>. To get the alias name and alias ARN, use <code>ListAliases</code>.</p>
225    pub fn get_key_id(&self) -> &::std::option::Option<::std::string::String> {
226        &self.key_id
227    }
228    /// <p>Specifies the message that was signed. You can submit a raw message of up to 4096 bytes, or a hash digest of the message. If you submit a digest, use the <code>MessageType</code> parameter with a value of <code>DIGEST</code>.</p>
229    /// <p>If the message specified here is different from the message that was signed, the signature verification fails. A message and its hash digest are considered to be the same message.</p>
230    /// This field is required.
231    pub fn message(mut self, input: ::aws_smithy_types::Blob) -> Self {
232        self.message = ::std::option::Option::Some(input);
233        self
234    }
235    /// <p>Specifies the message that was signed. You can submit a raw message of up to 4096 bytes, or a hash digest of the message. If you submit a digest, use the <code>MessageType</code> parameter with a value of <code>DIGEST</code>.</p>
236    /// <p>If the message specified here is different from the message that was signed, the signature verification fails. A message and its hash digest are considered to be the same message.</p>
237    pub fn set_message(mut self, input: ::std::option::Option<::aws_smithy_types::Blob>) -> Self {
238        self.message = input;
239        self
240    }
241    /// <p>Specifies the message that was signed. You can submit a raw message of up to 4096 bytes, or a hash digest of the message. If you submit a digest, use the <code>MessageType</code> parameter with a value of <code>DIGEST</code>.</p>
242    /// <p>If the message specified here is different from the message that was signed, the signature verification fails. A message and its hash digest are considered to be the same message.</p>
243    pub fn get_message(&self) -> &::std::option::Option<::aws_smithy_types::Blob> {
244        &self.message
245    }
246    /// <p>Tells KMS whether the value of the <code>Message</code> parameter should be hashed as part of the signing algorithm. Use <code>RAW</code> for unhashed messages; use <code>DIGEST</code> for message digests, which are already hashed; use <code>EXTERNAL_MU</code> for 64-byte representative μ used in ML-DSA signing as defined in NIST FIPS 204 Section 6.2.</p>
247    /// <p>When the value of <code>MessageType</code> is <code>RAW</code>, KMS uses the standard signing algorithm, which begins with a hash function. When the value is <code>DIGEST</code>, KMS skips the hashing step in the signing algorithm. When the value is <code>EXTERNAL_MU</code> KMS skips the concatenated hashing of the public key hash and the message done in the ML-DSA signing algorithm.</p><important>
248    /// <p>Use the <code>DIGEST</code> or <code>EXTERNAL_MU</code> value only when the value of the <code>Message</code> parameter is a message digest. If you use the <code>DIGEST</code> value with an unhashed message, the security of the signing operation can be compromised.</p>
249    /// </important>
250    /// <p>When using ECC_NIST_EDWARDS25519 KMS keys:</p>
251    /// <ul>
252    /// <li>
253    /// <p>ED25519_SHA_512 signing algorithm requires KMS <code>MessageType:RAW</code></p></li>
254    /// <li>
255    /// <p>ED25519_PH_SHA_512 signing algorithm requires KMS <code>MessageType:DIGEST</code></p></li>
256    /// </ul><important>
257    /// <p>When you specify the ED25519_PH_SHA_512 signing algorithm with <code>MessageType:DIGEST</code>, KMS still performs the SHA-512 prehash described in <a href="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf#page=39">Step 1 of Section 7.8.1 in FIPS 186-5</a>. This means the input is hashed twice: once by you and once by KMS.</p>
258    /// </important>
259    /// <p>When the value of <code>MessageType</code> is <code>DIGEST</code>, the length of the <code>Message</code> value must match the length of hashed messages for the specified signing algorithm.</p>
260    /// <p>When the value of <code>MessageType</code> is <code>EXTERNAL_MU</code> the length of the <code>Message</code> value must be 64 bytes.</p>
261    /// <p>You can submit a message digest and omit the <code>MessageType</code> or specify <code>RAW</code> so the digest is hashed again while signing. However, if the signed message is hashed once while signing, but twice while verifying, verification fails, even when the message hasn't changed.</p>
262    /// <p>The hashing algorithm that <code>Verify</code> uses is based on the <code>SigningAlgorithm</code> value.</p>
263    /// <ul>
264    /// <li>
265    /// <p>Signing algorithms that end in SHA_256 use the SHA_256 hashing algorithm.</p></li>
266    /// <li>
267    /// <p>Signing algorithms that end in SHA_384 use the SHA_384 hashing algorithm.</p></li>
268    /// <li>
269    /// <p>Signing algorithms that end in SHA_512 use the SHA_512 hashing algorithm.</p></li>
270    /// <li>
271    /// <p>Signing algorithms that end in SHAKE_256 use the SHAKE_256 hashing algorithm.</p></li>
272    /// <li>
273    /// <p>SM2DSA uses the SM3 hashing algorithm. For details, see <a href="https://docs.aws.amazon.com/kms/latest/developerguide/offline-operations.html#key-spec-sm-offline-verification">Offline verification with SM2 key pairs</a>.</p></li>
274    /// </ul>
275    pub fn message_type(mut self, input: crate::types::MessageType) -> Self {
276        self.message_type = ::std::option::Option::Some(input);
277        self
278    }
279    /// <p>Tells KMS whether the value of the <code>Message</code> parameter should be hashed as part of the signing algorithm. Use <code>RAW</code> for unhashed messages; use <code>DIGEST</code> for message digests, which are already hashed; use <code>EXTERNAL_MU</code> for 64-byte representative μ used in ML-DSA signing as defined in NIST FIPS 204 Section 6.2.</p>
280    /// <p>When the value of <code>MessageType</code> is <code>RAW</code>, KMS uses the standard signing algorithm, which begins with a hash function. When the value is <code>DIGEST</code>, KMS skips the hashing step in the signing algorithm. When the value is <code>EXTERNAL_MU</code> KMS skips the concatenated hashing of the public key hash and the message done in the ML-DSA signing algorithm.</p><important>
281    /// <p>Use the <code>DIGEST</code> or <code>EXTERNAL_MU</code> value only when the value of the <code>Message</code> parameter is a message digest. If you use the <code>DIGEST</code> value with an unhashed message, the security of the signing operation can be compromised.</p>
282    /// </important>
283    /// <p>When using ECC_NIST_EDWARDS25519 KMS keys:</p>
284    /// <ul>
285    /// <li>
286    /// <p>ED25519_SHA_512 signing algorithm requires KMS <code>MessageType:RAW</code></p></li>
287    /// <li>
288    /// <p>ED25519_PH_SHA_512 signing algorithm requires KMS <code>MessageType:DIGEST</code></p></li>
289    /// </ul><important>
290    /// <p>When you specify the ED25519_PH_SHA_512 signing algorithm with <code>MessageType:DIGEST</code>, KMS still performs the SHA-512 prehash described in <a href="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf#page=39">Step 1 of Section 7.8.1 in FIPS 186-5</a>. This means the input is hashed twice: once by you and once by KMS.</p>
291    /// </important>
292    /// <p>When the value of <code>MessageType</code> is <code>DIGEST</code>, the length of the <code>Message</code> value must match the length of hashed messages for the specified signing algorithm.</p>
293    /// <p>When the value of <code>MessageType</code> is <code>EXTERNAL_MU</code> the length of the <code>Message</code> value must be 64 bytes.</p>
294    /// <p>You can submit a message digest and omit the <code>MessageType</code> or specify <code>RAW</code> so the digest is hashed again while signing. However, if the signed message is hashed once while signing, but twice while verifying, verification fails, even when the message hasn't changed.</p>
295    /// <p>The hashing algorithm that <code>Verify</code> uses is based on the <code>SigningAlgorithm</code> value.</p>
296    /// <ul>
297    /// <li>
298    /// <p>Signing algorithms that end in SHA_256 use the SHA_256 hashing algorithm.</p></li>
299    /// <li>
300    /// <p>Signing algorithms that end in SHA_384 use the SHA_384 hashing algorithm.</p></li>
301    /// <li>
302    /// <p>Signing algorithms that end in SHA_512 use the SHA_512 hashing algorithm.</p></li>
303    /// <li>
304    /// <p>Signing algorithms that end in SHAKE_256 use the SHAKE_256 hashing algorithm.</p></li>
305    /// <li>
306    /// <p>SM2DSA uses the SM3 hashing algorithm. For details, see <a href="https://docs.aws.amazon.com/kms/latest/developerguide/offline-operations.html#key-spec-sm-offline-verification">Offline verification with SM2 key pairs</a>.</p></li>
307    /// </ul>
308    pub fn set_message_type(mut self, input: ::std::option::Option<crate::types::MessageType>) -> Self {
309        self.message_type = input;
310        self
311    }
312    /// <p>Tells KMS whether the value of the <code>Message</code> parameter should be hashed as part of the signing algorithm. Use <code>RAW</code> for unhashed messages; use <code>DIGEST</code> for message digests, which are already hashed; use <code>EXTERNAL_MU</code> for 64-byte representative μ used in ML-DSA signing as defined in NIST FIPS 204 Section 6.2.</p>
313    /// <p>When the value of <code>MessageType</code> is <code>RAW</code>, KMS uses the standard signing algorithm, which begins with a hash function. When the value is <code>DIGEST</code>, KMS skips the hashing step in the signing algorithm. When the value is <code>EXTERNAL_MU</code> KMS skips the concatenated hashing of the public key hash and the message done in the ML-DSA signing algorithm.</p><important>
314    /// <p>Use the <code>DIGEST</code> or <code>EXTERNAL_MU</code> value only when the value of the <code>Message</code> parameter is a message digest. If you use the <code>DIGEST</code> value with an unhashed message, the security of the signing operation can be compromised.</p>
315    /// </important>
316    /// <p>When using ECC_NIST_EDWARDS25519 KMS keys:</p>
317    /// <ul>
318    /// <li>
319    /// <p>ED25519_SHA_512 signing algorithm requires KMS <code>MessageType:RAW</code></p></li>
320    /// <li>
321    /// <p>ED25519_PH_SHA_512 signing algorithm requires KMS <code>MessageType:DIGEST</code></p></li>
322    /// </ul><important>
323    /// <p>When you specify the ED25519_PH_SHA_512 signing algorithm with <code>MessageType:DIGEST</code>, KMS still performs the SHA-512 prehash described in <a href="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf#page=39">Step 1 of Section 7.8.1 in FIPS 186-5</a>. This means the input is hashed twice: once by you and once by KMS.</p>
324    /// </important>
325    /// <p>When the value of <code>MessageType</code> is <code>DIGEST</code>, the length of the <code>Message</code> value must match the length of hashed messages for the specified signing algorithm.</p>
326    /// <p>When the value of <code>MessageType</code> is <code>EXTERNAL_MU</code> the length of the <code>Message</code> value must be 64 bytes.</p>
327    /// <p>You can submit a message digest and omit the <code>MessageType</code> or specify <code>RAW</code> so the digest is hashed again while signing. However, if the signed message is hashed once while signing, but twice while verifying, verification fails, even when the message hasn't changed.</p>
328    /// <p>The hashing algorithm that <code>Verify</code> uses is based on the <code>SigningAlgorithm</code> value.</p>
329    /// <ul>
330    /// <li>
331    /// <p>Signing algorithms that end in SHA_256 use the SHA_256 hashing algorithm.</p></li>
332    /// <li>
333    /// <p>Signing algorithms that end in SHA_384 use the SHA_384 hashing algorithm.</p></li>
334    /// <li>
335    /// <p>Signing algorithms that end in SHA_512 use the SHA_512 hashing algorithm.</p></li>
336    /// <li>
337    /// <p>Signing algorithms that end in SHAKE_256 use the SHAKE_256 hashing algorithm.</p></li>
338    /// <li>
339    /// <p>SM2DSA uses the SM3 hashing algorithm. For details, see <a href="https://docs.aws.amazon.com/kms/latest/developerguide/offline-operations.html#key-spec-sm-offline-verification">Offline verification with SM2 key pairs</a>.</p></li>
340    /// </ul>
341    pub fn get_message_type(&self) -> &::std::option::Option<crate::types::MessageType> {
342        &self.message_type
343    }
344    /// <p>The signature that the <code>Sign</code> operation generated.</p>
345    /// This field is required.
346    pub fn signature(mut self, input: ::aws_smithy_types::Blob) -> Self {
347        self.signature = ::std::option::Option::Some(input);
348        self
349    }
350    /// <p>The signature that the <code>Sign</code> operation generated.</p>
351    pub fn set_signature(mut self, input: ::std::option::Option<::aws_smithy_types::Blob>) -> Self {
352        self.signature = input;
353        self
354    }
355    /// <p>The signature that the <code>Sign</code> operation generated.</p>
356    pub fn get_signature(&self) -> &::std::option::Option<::aws_smithy_types::Blob> {
357        &self.signature
358    }
359    /// <p>The signing algorithm that was used to sign the message. If you submit a different algorithm, the signature verification fails.</p>
360    /// This field is required.
361    pub fn signing_algorithm(mut self, input: crate::types::SigningAlgorithmSpec) -> Self {
362        self.signing_algorithm = ::std::option::Option::Some(input);
363        self
364    }
365    /// <p>The signing algorithm that was used to sign the message. If you submit a different algorithm, the signature verification fails.</p>
366    pub fn set_signing_algorithm(mut self, input: ::std::option::Option<crate::types::SigningAlgorithmSpec>) -> Self {
367        self.signing_algorithm = input;
368        self
369    }
370    /// <p>The signing algorithm that was used to sign the message. If you submit a different algorithm, the signature verification fails.</p>
371    pub fn get_signing_algorithm(&self) -> &::std::option::Option<crate::types::SigningAlgorithmSpec> {
372        &self.signing_algorithm
373    }
374    /// Appends an item to `grant_tokens`.
375    ///
376    /// To override the contents of this collection use [`set_grant_tokens`](Self::set_grant_tokens).
377    ///
378    /// <p>A list of grant tokens.</p>
379    /// <p>Use a grant token when your permission to call this operation comes from a new grant that has not yet achieved <i>eventual consistency</i>. For more information, see <a href="https://docs.aws.amazon.com/kms/latest/developerguide/grants.html#grant_token">Grant token</a> and <a href="https://docs.aws.amazon.com/kms/latest/developerguide/using-grant-token.html">Using a grant token</a> in the <i>Key Management Service Developer Guide</i>.</p>
380    pub fn grant_tokens(mut self, input: impl ::std::convert::Into<::std::string::String>) -> Self {
381        let mut v = self.grant_tokens.unwrap_or_default();
382        v.push(input.into());
383        self.grant_tokens = ::std::option::Option::Some(v);
384        self
385    }
386    /// <p>A list of grant tokens.</p>
387    /// <p>Use a grant token when your permission to call this operation comes from a new grant that has not yet achieved <i>eventual consistency</i>. For more information, see <a href="https://docs.aws.amazon.com/kms/latest/developerguide/grants.html#grant_token">Grant token</a> and <a href="https://docs.aws.amazon.com/kms/latest/developerguide/using-grant-token.html">Using a grant token</a> in the <i>Key Management Service Developer Guide</i>.</p>
388    pub fn set_grant_tokens(mut self, input: ::std::option::Option<::std::vec::Vec<::std::string::String>>) -> Self {
389        self.grant_tokens = input;
390        self
391    }
392    /// <p>A list of grant tokens.</p>
393    /// <p>Use a grant token when your permission to call this operation comes from a new grant that has not yet achieved <i>eventual consistency</i>. For more information, see <a href="https://docs.aws.amazon.com/kms/latest/developerguide/grants.html#grant_token">Grant token</a> and <a href="https://docs.aws.amazon.com/kms/latest/developerguide/using-grant-token.html">Using a grant token</a> in the <i>Key Management Service Developer Guide</i>.</p>
394    pub fn get_grant_tokens(&self) -> &::std::option::Option<::std::vec::Vec<::std::string::String>> {
395        &self.grant_tokens
396    }
397    /// <p>Checks if your request will succeed. <code>DryRun</code> is an optional parameter.</p>
398    /// <p>To learn more about how to use this parameter, see <a href="https://docs.aws.amazon.com/kms/latest/developerguide/testing-permissions.html">Testing your permissions</a> in the <i>Key Management Service Developer Guide</i>.</p>
399    pub fn dry_run(mut self, input: bool) -> Self {
400        self.dry_run = ::std::option::Option::Some(input);
401        self
402    }
403    /// <p>Checks if your request will succeed. <code>DryRun</code> is an optional parameter.</p>
404    /// <p>To learn more about how to use this parameter, see <a href="https://docs.aws.amazon.com/kms/latest/developerguide/testing-permissions.html">Testing your permissions</a> in the <i>Key Management Service Developer Guide</i>.</p>
405    pub fn set_dry_run(mut self, input: ::std::option::Option<bool>) -> Self {
406        self.dry_run = input;
407        self
408    }
409    /// <p>Checks if your request will succeed. <code>DryRun</code> is an optional parameter.</p>
410    /// <p>To learn more about how to use this parameter, see <a href="https://docs.aws.amazon.com/kms/latest/developerguide/testing-permissions.html">Testing your permissions</a> in the <i>Key Management Service Developer Guide</i>.</p>
411    pub fn get_dry_run(&self) -> &::std::option::Option<bool> {
412        &self.dry_run
413    }
414    /// Consumes the builder and constructs a [`VerifyInput`](crate::operation::verify::VerifyInput).
415    pub fn build(self) -> ::std::result::Result<crate::operation::verify::VerifyInput, ::aws_smithy_types::error::operation::BuildError> {
416        ::std::result::Result::Ok(crate::operation::verify::VerifyInput {
417            key_id: self.key_id,
418            message: self.message,
419            message_type: self.message_type,
420            signature: self.signature,
421            signing_algorithm: self.signing_algorithm,
422            grant_tokens: self.grant_tokens,
423            dry_run: self.dry_run,
424        })
425    }
426}
427impl ::std::fmt::Debug for VerifyInputBuilder {
428    fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
429        let mut formatter = f.debug_struct("VerifyInputBuilder");
430        formatter.field("key_id", &self.key_id);
431        formatter.field("message", &"*** Sensitive Data Redacted ***");
432        formatter.field("message_type", &self.message_type);
433        formatter.field("signature", &self.signature);
434        formatter.field("signing_algorithm", &self.signing_algorithm);
435        formatter.field("grant_tokens", &self.grant_tokens);
436        formatter.field("dry_run", &self.dry_run);
437        formatter.finish()
438    }
439}