SSESpecification - Amazon DynamoDB
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

SSESpecification

Represents the settings used to enable server-side encryption.

Contents

Note

In the following list, the required parameters are described first.

Enabled

Indicates whether server-side encryption is done using an Amazon managed key or an Amazon owned key. If enabled (true), server-side encryption type is set to KMS and an Amazon managed key is used (Amazon KMS charges apply). If disabled (false) or not specified, server-side encryption is set to Amazon owned key.

Type: Boolean

Required: No

KMSMasterKeyId

The Amazon KMS key that should be used for the Amazon KMS encryption. To specify a key, use its key ID, Amazon Resource Name (ARN), alias name, or alias ARN. Note that you should only provide this parameter if the key is different from the default DynamoDB key alias/aws/dynamodb.

Type: String

Required: No

SSEType

Server-side encryption type. The only supported value is:

  • KMS - Server-side encryption that uses Amazon Key Management Service. The key is stored in your account and is managed by Amazon KMS (Amazon KMS charges apply).

Type: String

Valid Values: AES256 | KMS

Required: No

See Also

For more information about using this API in one of the language-specific Amazon SDKs, see the following: