class Aws::DynamoDB::Types::SSESpecification

Represents the settings used to enable server-side encryption.

@note When making an API call, you may pass SSESpecification

data as a hash:

    {
      enabled: false,
      sse_type: "AES256", # accepts AES256, KMS
      kms_master_key_id: "KMSMasterKeyId",
    }

@!attribute [rw] enabled

Indicates whether server-side encryption is done using an AWS
managed CMK or an AWS owned CMK. If enabled (true), server-side
encryption type is set to `KMS` and an AWS managed CMK is used (AWS
KMS charges apply). If disabled (false) or not specified,
server-side encryption is set to AWS owned CMK.
@return [Boolean]

@!attribute [rw] sse_type

Server-side encryption type. The only supported value is:

* `KMS` - Server-side encryption that uses AWS Key Management
  Service. The key is stored in your account and is managed by AWS
  KMS (AWS KMS charges apply).

^
@return [String]

@!attribute [rw] kms_master_key_id

The AWS KMS customer master key (CMK) that should be used for the
AWS KMS encryption. To specify a CMK, use its key ID, Amazon
Resource Name (ARN), alias name, or alias ARN. Note that you should
only provide this parameter if the key is different from the default
DynamoDB customer master key alias/aws/dynamodb.
@return [String]

@see docs.aws.amazon.com/goto/WebAPI/dynamodb-2012-08-10/SSESpecification AWS API Documentation

Constants

SENSITIVE