SqlColumnEncryptionKeyStoreProvider.DecryptColumnEncryptionKeyAsync Method
Definition
Important
Some information relates to prerelease product that may be substantially modified before it’s released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
Asynchronously decrypts the specified encrypted value of a column encryption key. The encrypted value is expected to be encrypted using the column master key with the specified key path and using the specified algorithm.
public virtual System.Threading.Tasks.Task<byte[]> DecryptColumnEncryptionKeyAsync(string masterKeyPath, string encryptionAlgorithm, byte[] encryptedColumnEncryptionKey, System.Threading.CancellationToken cancellationToken = default);
abstract member DecryptColumnEncryptionKeyAsync : string * string * byte[] * System.Threading.CancellationToken -> System.Threading.Tasks.Task<byte[]>
override this.DecryptColumnEncryptionKeyAsync : string * string * byte[] * System.Threading.CancellationToken -> System.Threading.Tasks.Task<byte[]>
Public Overridable Function DecryptColumnEncryptionKeyAsync (masterKeyPath As String, encryptionAlgorithm As String, encryptedColumnEncryptionKey As Byte(), Optional cancellationToken As CancellationToken = Nothing) As Task(Of Byte())
Parameters
- masterKeyPath
- String
The column master key path. The path format is specific to the key store provider implementation (e.g. a thumbprint for the certificate store, or a key identifier URL for Azure Key Vault).
- encryptionAlgorithm
- String
The encryption algorithm name. For example,
RSA_OAEP.
- encryptedColumnEncryptionKey
- Byte[]
The encrypted column encryption key.
- cancellationToken
- CancellationToken
A token to cancel the asynchronous operation.
Returns
A task that returns a Byte array representing the decrypted column encryption key on completion.
Remarks
The default implementation first checks the cancellationToken and returns a canceled task if cancellation has been requested. Otherwise, it calls the synchronous DecryptColumnEncryptionKey(String, String, Byte[]) method and wraps the result in a completed task. If the synchronous method throws, the exception is caught and a faulted task is returned rather than throwing synchronously.
Derived classes that perform I/O (such as calls to Azure Key Vault) should override this method with a truly asynchronous implementation that honors the cancellation token.