Decrypt exactly ONE cipher block — block.length must equal
KeyMetadata.modulusLength — and return the plaintext.
One call is one HSM/KMS operation by design: callers own the multi-block loop (and may issue blocks concurrently), so a provider never has to reimplement it and round trips stay visible.
OptionaldecryptSynchronous decryptBlock. Local keys only.
The declared key facts. Stable for the lifetime of the object.
OptionalgetSynchronous getKeyMetadata. Local keys only.
OptionalgetThe public half of the key, SPKI-encoded DER.
Optional, but strongly recommended: certificate/key match checks and CSR generation over an opaque key both need it, and are unavailable (with a clear error) without it.
Sign data and return the signature (modulusLength bytes for RSA).
OptionalsignSynchronous sign. Local keys only; remote providers omit it.
Opaque private-key operations: an object that can use a private key — sign, decrypt — without the key ever being obtainable through it.
This is the secure-channel/session-side sibling of CaSigner (which covers X509 issuance and is sign-only): shaped after cloud KMS/HSM APIs, so the OPC UA application instance key can live in a TPM, HSM, KMS or OS keystore, non-exportable, while node-opcua drives it through this interface. Implementations wrap a local in-process key, a PKCS#11 token, a cloud KMS client — the caller cannot tell the difference, and this interface never asks for the key itself.
The three required methods are asynchronous, because a remote key is. The optional
*Synctrio is the fast path a local-key implementation provides so that code paths which are synchronous by contract (OPC UA chunk assembly) keep working unchanged with local keys; remote implementations simply omit them, and callers choose a path via hasSyncKeyOperations.