NodeOPCUA API Documentation
    Preparing search index...

    Interface IKeyOperations

    Opaque private-key operations: an object that can use a private key — sign, decrypt — without the key ever being obtainable through it.

    This is the secure-channel/session-side sibling of CaSigner (which covers X509 issuance and is sign-only): shaped after cloud KMS/HSM APIs, so the OPC UA application instance key can live in a TPM, HSM, KMS or OS keystore, non-exportable, while node-opcua drives it through this interface. Implementations wrap a local in-process key, a PKCS#11 token, a cloud KMS client — the caller cannot tell the difference, and this interface never asks for the key itself.

    The three required methods are asynchronous, because a remote key is. The optional *Sync trio is the fast path a local-key implementation provides so that code paths which are synchronous by contract (OPC UA chunk assembly) keep working unchanged with local keys; remote implementations simply omit them, and callers choose a path via hasSyncKeyOperations.

    interface IKeyOperations {
        decryptBlock(
            block: Uint8Array,
            params: AsymmetricDecryptParams,
        ): Promise<Buffer<ArrayBufferLike>>;
        decryptBlockSync?(
            block: Uint8Array,
            params: AsymmetricDecryptParams,
        ): Buffer;
        getKeyMetadata(): Promise<KeyMetadata>;
        getKeyMetadataSync?(): KeyMetadata;
        getPublicKey?(): Promise<ArrayBuffer>;
        sign(
            data: Uint8Array,
            params: AsymmetricSignParams,
        ): Promise<Buffer<ArrayBufferLike>>;
        signSync?(data: Uint8Array, params: AsymmetricSignParams): Buffer;
    }
    Index
    • Decrypt exactly ONE cipher block — block.length must equal KeyMetadata.modulusLength — and return the plaintext.

      One call is one HSM/KMS operation by design: callers own the multi-block loop (and may issue blocks concurrently), so a provider never has to reimplement it and round trips stay visible.

      Parameters

      • block: Uint8Array
      • params: AsymmetricDecryptParams

      Returns Promise<Buffer<ArrayBufferLike>>

    • Synchronous decryptBlock. Local keys only.

      Parameters

      • block: Uint8Array
      • params: AsymmetricDecryptParams

      Returns Buffer

    • The declared key facts. Stable for the lifetime of the object.

      Returns Promise<KeyMetadata>

    • Synchronous getKeyMetadata. Local keys only.

      Returns KeyMetadata

    • The public half of the key, SPKI-encoded DER.

      Optional, but strongly recommended: certificate/key match checks and CSR generation over an opaque key both need it, and are unavailable (with a clear error) without it.

      Returns Promise<ArrayBuffer>

    • Sign data and return the signature (modulusLength bytes for RSA).

      Parameters

      • data: Uint8Array
      • params: AsymmetricSignParams

      Returns Promise<Buffer<ArrayBufferLike>>

    • Synchronous sign. Local keys only; remote providers omit it.

      Parameters

      • data: Uint8Array
      • params: AsymmetricSignParams

      Returns Buffer