Queries the encryption key of a MongoDB instance.
Operation description
When you call the DescribeDBInstanceEncryptionKey operation, the instance must have transparent data encryption (TDE) enabled in BYOK mode. You can call the ModifyDBInstanceTDE operation to enable TDE.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
dds:DescribeDBInstanceEncryptionKey |
get |
*Instance
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| DBInstanceId |
string |
Yes |
The instance ID. |
dds-bp2235**** |
| EncryptionKey |
string |
No |
The custom key for the instance. You can call the DescribeUserEncryptionKeyList operation to query the list of custom keys for an ApsaraDB for MongoDB instance. |
2axxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The data returned. |
||
| Origin |
string |
The source of the key for the instance. |
Aliyun_KMS |
| Description |
string |
The description of the key for the instance. |
key description example |
| RequestId |
string |
The request ID. |
783C2062-A2D3-4EA8-88AD-E43F990C23BB |
| EncryptionKeyStatus |
string |
Indicates whether the key for the instance is enabled. Valid values:
|
Enabled |
| MaterialExpireTime |
string |
The expiration time of the key for the instance. The time is displayed in UTC. If the parameter is left empty, the key for the instance will not expire. |
2020-07-06T18:22:03Z |
| KeyUsage |
string |
The purpose of the key for the instance. |
ENCRYPT/DECRYPT |
| EncryptionKey |
string |
The key for the instance. |
2axxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx |
| Creator |
string |
The UID of the key creator. |
123456 |
| DeleteDate |
string |
The scheduled time when the key for the instance will be deleted. If the parameter is left empty, the key will not be deleted. |
2020-07-06T18:22:03Z |
Examples
Success response
JSON format
{
"Origin": "Aliyun_KMS",
"Description": "key description example",
"RequestId": "783C2062-A2D3-4EA8-88AD-E43F990C23BB",
"EncryptionKeyStatus": "Enabled",
"MaterialExpireTime": "2020-07-06T18:22:03Z",
"KeyUsage": "ENCRYPT/DECRYPT",
"EncryptionKey": "2axxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
"Creator": "123456",
"DeleteDate": "2020-07-06T18:22:03Z"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 403 | INVALID_INSNAME_REGIONID_EMPTY | The insName and regionId can't be all empty | |
| 403 | NO_ACTIVE_BYOK | This custins no active byok. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.