Azure.Security.KeyVault.Keys (.NET)
Azure Key Vault および Managed HSM 内の暗号鍵を管理するためのクライアント ライブラリ。
インストール
dotnet add package Azure.Security.KeyVault.Keys
dotnet add package Azure.Identity
現在のバージョン: 4.7.0 (安定版)
環境変数
KEY_VAULT_NAME= # 必須: Key Vault の名前
AZURE_KEYVAULT_URL=https://.vault.azure.net # オプション: Key Vault の完全な URL
AZURE_TOKEN_CREDENTIALS=prod # 本番環境で DefaultAzureCredential を使用する場合にのみ必須
クライアント階層
KeyClient(キー管理)
├── CreateKey / CreateRsaKey / CreateEcKey
├── GetKey / GetKeys
├── UpdateKeyProperties
├── DeleteKey / PurgeDeletedKey
├── BackupKey / RestoreKey
└── GetCryptographyClient() → CryptographyClient
CryptographyClient (暗号化操作)
├── Encrypt / Decrypt
├── WrapKey / UnwrapKey
├── 署名 / 検証
└── データの署名 / データの検証
KeyResolver(鍵の解決)
└── Resolve(keyId) → CryptographyClient
認証
Microsoft Entra トークン資格情報
using Azure.Identity;
using Azure.Security.KeyVault.Keys;
var keyVaultName = Environment.GetEnvironmentVariable("KEY_VAULT_NAME");
var kvUri = $"https://{keyVaultName}.vault.azure.net";
// ローカル開発環境:DefaultAzureCredential。本番環境:AZURE_TOKEN_CREDENTIALS=prod または AZURE_TOKEN_CREDENTIALS=を設定
var credential = new DefaultAzureCredential(
DefaultAzureCredential.DefaultEnvironmentVariableName
);
// または、本番環境では特定の認証情報を直接使用:
// https://learn.microsoft.com/dotnet/api/overview/azure/identity-readme?view=azure-dotnet#credential-classes を参照
// var credential = new ManagedIdentityCredential();
var client = new KeyClient(new Uri(kvUri), credential);
サービスプリンシパル
var credential = new ClientSecretCredential(
tenantId: "",
clientId: "",
clientSecret: "");
var client = new KeyClient(new Uri(kvUri), credential);
キー管理
キーの作成
// RSA キーの作成
KeyVaultKey rsaKey = await client.CreateKeyAsync("my-rsa-key", KeyType.Rsa);
Console.WriteLine($"キーを作成しました: {rsaKey.Name}, タイプ: {rsaKey.KeyType}");
// オプションを指定してRSAキーを作成
var rsaOptions = new CreateRsaKeyOptions("my-rsa-key-2048")
{
KeySize = 2048,
HardwareProtected = false, // HSMで保護されている場合はtrue
ExpiresOn = DateTimeOffset.UtcNow.AddYears(1),
NotBefore = DateTimeOffset.UtcNow,
Enabled = true
};
rsaOptions.KeyOperations.Add(KeyOperation.Encrypt);
rsaOptions.KeyOperations.Add(KeyOperation.Decrypt);
KeyVaultKey rsaKey2 = await client.CreateRsaKeyAsync(rsaOptions);
// EC キーの作成
var ecOptions = new CreateEcKeyOptions("my-ec-key")
{
CurveName = KeyCurveName.P256,
HardwareProtected = true // HSMによる保護
};
KeyVaultKey ecKey = await client.CreateEcKeyAsync(ecOptions);
// ラップ/アンラップ用のOct(対称)キーを作成
var octOptions = new CreateOctKeyOptions("my-oct-key")
{
KeySize = 256,
HardwareProtected = true
};
KeyVaultKey octKey = await client.CreateOctKeyAsync(octOptions);
キーの取得
// 特定のキー(最新バージョン)を取得
KeyVaultKey key = await client.GetKeyAsync("my-rsa-key");
Console.WriteLine($"キー ID: {key.Id}");
Console.WriteLine($"キーの種類: {key.KeyType}");
Console.WriteLine($"バージョン: {key.Properties.Version}");
// 特定のバージョンを取得
KeyVaultKey keyVersion = await client.GetKeyAsync("my-rsa-key", "version-id");
// すべてのキーを一覧表示
await foreach (KeyProperties keyProps in client.GetPropertiesOfKeysAsync())
{
Console.WriteLine($"キー: {keyProps.Name}, 有効: {keyProps.Enabled}");
}
// キーのバージョンを一覧表示
await foreach (KeyProperties version in client.GetPropertiesOfKeyVersionsAsync("my-rsa-key"))
{
Console.WriteLine($"バージョン: {version.Version}, 作成日時: {version.CreatedOn}");
}
キーのプロパティを更新する
KeyVaultKey key = await client.GetKeyAsync("my-rsa-key");
key.Properties.ExpiresOn = DateTimeOffset.UtcNow.AddYears(2);
key.Properties.Tags["environment"] = "production";
KeyVaultKey updatedKey = await client.UpdateKeyPropertiesAsync(key.Properties);
キーの削除とパージ
// 削除操作を開始
DeleteKeyOperation operation = await client.StartDeleteKeyAsync("my-rsa-key");
// 削除が完了するまで待機(パージの前に必要)
await operation.WaitForCompletionAsync();
Console.WriteLine($"削除されたキーのパージ予定日: {operation.Value.ScheduledPurgeDate}");
// すぐにパージする(ソフト削除が有効な場合)
await client.PurgeDeletedKeyAsync("my-rsa-key");
// または、削除されたキーを復元する
KeyVaultKey recoveredKey = await client.StartRecoverDeletedKeyAsync("my-rsa-key");
バックアップと復元
// キーのバックアップ
byte[] backup = await client.BackupKeyAsync("my-rsa-key");
await File.WriteAllBytesAsync("key-backup.bin", backup);
// キーの復元
byte[] backupData = await File.ReadAllBytesAsync("key-backup.bin");
KeyVaultKey restoredKey = await client.RestoreKeyBackupAsync(backupData);
暗号化操作
CryptographyClientの取得
// KeyClient から取得
KeyVaultKey key = await client.GetKeyAsync("my-rsa-key");
CryptographyClient cryptoClient = client.GetCryptographyClient(
key.Name,
key.Properties.Version);
// または、キー ID を使用して直接作成
CryptographyClient cryptoClient = new CryptographyClient(
new Uri("https://myvault.vault.azure.net/keys/my-rsa-key/version"),
new DefaultAzureCredential());
暗号化と復号
byte[] plaintext = Encoding.UTF8.GetBytes("暗号化する秘密のメッセージ");
// 暗号化
EncryptResult encryptResult = await cryptoClient.EncryptAsync(
EncryptionAlgorithm.RsaOaep256,
plaintext);
Console.WriteLine($"暗号化済み: {Convert.ToBase64String(encryptResult.Ciphertext)}");
// 復号
DecryptResult decryptResult = await cryptoClient.DecryptAsync(
EncryptionAlgorithm.RsaOaep256,
encryptResult.Ciphertext);
string decrypted = Encoding.UTF8.GetString(decryptResult.Plaintext);
Console.WriteLine($"復号済み: {decrypted}");
鍵のラッピングとアンラッピング
// ラップする鍵(例:AES鍵)
byte[] keyToWrap = new byte[32]; // 256ビット鍵
RandomNumberGenerator.Fill(keyToWrap);
// 鍵のラッピング
WrapResult wrapResult = await cryptoClient.WrapKeyAsync(
KeyWrapAlgorithm.RsaOaep256,
keyToWrap);
// 鍵の復号
UnwrapResult unwrapResult = await cryptoClient.UnwrapKeyAsync(
KeyWrapAlgorithm.RsaOaep256,
wrapResult.EncryptedKey);
署名と検証
// 署名対象のデータ
byte[] data = Encoding.UTF8.GetBytes("署名対象のデータ");
// データへの署名(内部でハッシュを計算)
SignResult signResult = await cryptoClient.SignDataAsync(
SignatureAlgorithm.RS256,
data);
// 署名の検証
VerifyResult verifyResult = await cryptoClient.VerifyDataAsync(
SignatureAlgorithm.RS256,
data,
signResult.Signature);
Console.WriteLine($"署名は有効です: {verifyResult.IsValid}");
// または、事前に計算されたハッシュに署名する
using var sha256 = SHA256.Create();
byte[] hash = sha256.ComputeHash(data);
SignResult signHashResult = await cryptoClient.SignAsync(
SignatureAlgorithm.RS256,
hash);
キーリゾルバー
using Azure.Security.KeyVault.Keys.Cryptography;
var resolver = new KeyResolver(new DefaultAzureCredential());
// ID からキーを解決して CryptographyClient を取得
CryptographyClient cryptoClient = await resolver.ResolveAsync(
new Uri("https://myvault.vault.azure.net/keys/my-key/version"));
// 暗号化に使用
EncryptResult result = await cryptoClient.EncryptAsync(
EncryptionAlgorithm.RsaOaep256,
plaintext);
鍵のローテーション
// キーのローテーション(新しいバージョンを作成)
KeyVaultKey rotatedKey = await client.RotateKeyAsync("my-rsa-key");
Console.WriteLine($"新しいバージョン: {rotatedKey.Properties.Version}");
// ローテーション ポリシーを取得
KeyRotationPolicy policy = await client.GetKeyRotationPolicyAsync("my-rsa-key");
// ローテーションポリシーを更新
policy.ExpiresIn = "P90D"; // 90 日
policy.LifetimeActions.Add(new KeyRotationLifetimeAction
{
Action = KeyRotationPolicyAction.Rotate,
TimeBeforeExpiry = "P30D" // 有効期限の30日前にローテーション
});
await client.UpdateKeyRotationPolicyAsync("my-rsa-key", policy);
キーの種類のリファレンス
| タイプ |
目的 |
KeyClient |
鍵管理操作 |
CryptographyClient |
暗号化操作 |
KeyResolver |
キーIDをCryptographyClientに解決する |
KeyVaultKey |
暗号素材を含むキー |
KeyProperties |
キーのメタデータ(暗号素材なし) |
CreateRsaKeyOptions |
RSA 鍵の作成オプション |
CreateEcKeyOptions |
EC 鍵の作成オプション |
CreateOctKeyOptions |
対称鍵のオプション |
EncryptResult |
暗号化結果 |
DecryptResult |
復号結果 |
SignResult |
SignResult署名結果 |
VerifyResult |
検証結果 |
WrapResult |
Key wrap result |
UnwrapResult |
鍵のアンラップ結果 |
アルゴリズムリファレンス
暗号化アルゴリズム
| アルゴリズム |
鍵の種類 |
説明 |
RsaOaep |
RSA |
RSA-OAEP |
RsaOaep256 |
RSA |
RSA-OAEP-256 |
Rsa15 |
RSA |
RSA 1.5 (旧版) |
A128Gcm |
Oct |
AES-128-GCM |
A256Gcm |
10月 |
AES-256-GCM |
署名アルゴリズム
| アルゴリズム |
鍵の種類 |
説明 |
RS256 |
RSA |
RSASSA-PKCS1-v1_5SHA-256 |
RS384 |
RSA |
RSASSA-PKCS1-v1_5 SHA-384 |
RS512 |
RSA |
RSASSA-PKCS1-v1_5 SHA-512 |
PS256 |
RSA |
RSASSA-PSS SHA-256 |
ES256 |
EC |
ECDSA P-256 SHA-256 |
ES384 |
EC |
ECDSA P-384 SHA-384 |
ES512 |
EC |
ECDSA P-521 SHA-512 |
鍵ラップアルゴリズム
| アルゴリズム |
鍵の種類 |
説明 |
RsaOaep |
RSA |
RSA-OAEP |
RsaOaep256 |
RSA |
RSA-OAEP-256 |
A128KW |
10月 |
AES-128 キーラップ |
A256KW |
10月AES-128 キーラップA256KW |
AES-256 キーラップ |
ベストプラクティス
- 管理対象 ID を使用する— シークレットよりも
DefaultAzureCredentialを優先する
- ソフト削除を有効にする— 誤削除からの保護
- HSMで保護されたキーを使用する— 機密性の高いキーについては、
HardwareProtected = trueに設定する
- 鍵のローテーションを実装する— 自動ローテーションポリシーを使用する
- キー操作を制限する— 必要な
KeyOperationsのみを有効にする
- 有効期限を設定する— キーには常に `
ExpiresOn` を設定する
- 特定のバージョンを使用する— 本番環境ではバージョンを固定する
- CryptographyClientのキャッシュ— 複数の操作で再利用する
エラー処理
using Azure;
try
{
KeyVaultKey key = await client.GetKeyAsync("my-key");
}
catch (RequestFailedException ex) when (ex.Status == 404)
{
Console.WriteLine("キーが見つかりません");
}
catch (RequestFailedException ex) when (ex.Status == 403)
{
Console.WriteLine("アクセス拒否 - RBAC 権限を確認してください");
}
catch (RequestFailedException ex)
{
Console.WriteLine($"Key Vault エラー: {ex.Status} - {ex.Message}");
}
必要な RBAC ロール
| ロール |
権限 |
| Key Vault 暗号担当官 |
完全なキー管理 |
| Key Vault 暗号化ユーザー |
暗号化操作にキーを使用する |
| Key Vault リーダー |
キーのメタデータを読み取る |
関連する SDK
| SDK |
目的 |
インストール |
Azure.Security.KeyVault.Keys |
Keys(この SDK) |
dotnet add package Azure.Security.KeyVault.Keys |
Azure.Security.KeyVault.Secrets |
Secrets |
dotnet add package Azure.Security.KeyVault.Secrets |
Azure.Security.KeyVault.Certificates |
Certificates |
dotnet add package Azure.Security.KeyVault.Certificates |
Azure.Identity |
Authentication |
dotnet add package Azure.Identity |
参考リンク
| リソース |
URL |
| NuGet パッケージ |
https://www.nuget.org/packages/Azure.Security.KeyVault.Keys |
| APIリファレンス |
https://learn.microsoft.com/dotnet/api/azure.security.keyvault.keys |
| クイックスタート |
https://learn.microsoft.com/azure/key-vault/keys/quick-create-net |
| GitHub ソース |
https://github.com/Azure/azure-sdk-for-net/tree/main/sdk/keyvault/Azure.Security.KeyVault.Keys |
GitHubで見る
---
name: azure-security-keyvault-keys-dotnet
description: Manage cryptographic keys in Azure Key Vault and Managed HSM using the .NET SDK. Create, rotate, encrypt, decrypt, sign, and verify keys with KeyClient and CryptographyClient.
license: MIT
---
# Azure.Security.KeyVault.Keys (.NET)
Client library for managing cryptographic keys in Azure Key Vault and Managed HSM.
## Installation
```bash
dotnet add package Azure.Security.KeyVault.Keys
dotnet add package Azure.Identity
```
**Current Version**: 4.7.0 (stable)
## Environment Variables
```bash
KEY_VAULT_NAME=<your-key-vault-name> # Required: Key Vault name
AZURE_KEYVAULT_URL=https://<vault-name>.vault.azure.net # Optional: full Key Vault URL
AZURE_TOKEN_CREDENTIALS=prod # Required only if DefaultAzureCredential is used in production
```
## Client Hierarchy
```
KeyClient (key management)
├── CreateKey / CreateRsaKey / CreateEcKey
├── GetKey / GetKeys
├── UpdateKeyProperties
├── DeleteKey / PurgeDeletedKey
├── BackupKey / RestoreKey
└── GetCryptographyClient() → CryptographyClient
CryptographyClient (cryptographic operations)
├── Encrypt / Decrypt
├── WrapKey / UnwrapKey
├── Sign / Verify
└── SignData / VerifyData
KeyResolver (key resolution)
└── Resolve(keyId) → CryptographyClient
```
## Authentication
### Microsoft Entra Token Credential
```csharp
using Azure.Identity;
using Azure.Security.KeyVault.Keys;
var keyVaultName = Environment.GetEnvironmentVariable("KEY_VAULT_NAME");
var kvUri = $"https://{keyVaultName}.vault.azure.net";
// Local dev: DefaultAzureCredential. Production: set AZURE_TOKEN_CREDENTIALS=prod or AZURE_TOKEN_CREDENTIALS=<specific_credential>
var credential = new DefaultAzureCredential(
DefaultAzureCredential.DefaultEnvironmentVariableName
);
// Or use a specific credential directly in production:
// See https://learn.microsoft.com/dotnet/api/overview/azure/identity-readme?view=azure-dotnet#credential-classes
// var credential = new ManagedIdentityCredential();
var client = new KeyClient(new Uri(kvUri), credential);
```
### Service Principal
```csharp
var credential = new ClientSecretCredential(
tenantId: "<tenant-id>",
clientId: "<client-id>",
clientSecret: "<client-secret>");
var client = new KeyClient(new Uri(kvUri), credential);
```
## Key Management
### Create Keys
```csharp
// Create RSA key
KeyVaultKey rsaKey = await client.CreateKeyAsync("my-rsa-key", KeyType.Rsa);
Console.WriteLine($"Created key: {rsaKey.Name}, Type: {rsaKey.KeyType}");
// Create RSA key with options
var rsaOptions = new CreateRsaKeyOptions("my-rsa-key-2048")
{
KeySize = 2048,
HardwareProtected = false, // true for HSM-backed
ExpiresOn = DateTimeOffset.UtcNow.AddYears(1),
NotBefore = DateTimeOffset.UtcNow,
Enabled = true
};
rsaOptions.KeyOperations.Add(KeyOperation.Encrypt);
rsaOptions.KeyOperations.Add(KeyOperation.Decrypt);
KeyVaultKey rsaKey2 = await client.CreateRsaKeyAsync(rsaOptions);
// Create EC key
var ecOptions = new CreateEcKeyOptions("my-ec-key")
{
CurveName = KeyCurveName.P256,
HardwareProtected = true // HSM-backed
};
KeyVaultKey ecKey = await client.CreateEcKeyAsync(ecOptions);
// Create Oct (symmetric) key for wrap/unwrap
var octOptions = new CreateOctKeyOptions("my-oct-key")
{
KeySize = 256,
HardwareProtected = true
};
KeyVaultKey octKey = await client.CreateOctKeyAsync(octOptions);
```
### Retrieve Keys
```csharp
// Get specific key (latest version)
KeyVaultKey key = await client.GetKeyAsync("my-rsa-key");
Console.WriteLine($"Key ID: {key.Id}");
Console.WriteLine($"Key Type: {key.KeyType}");
Console.WriteLine($"Version: {key.Properties.Version}");
// Get specific version
KeyVaultKey keyVersion = await client.GetKeyAsync("my-rsa-key", "version-id");
// List all keys
await foreach (KeyProperties keyProps in client.GetPropertiesOfKeysAsync())
{
Console.WriteLine($"Key: {keyProps.Name}, Enabled: {keyProps.Enabled}");
}
// List key versions
await foreach (KeyProperties version in client.GetPropertiesOfKeyVersionsAsync("my-rsa-key"))
{
Console.WriteLine($"Version: {version.Version}, Created: {version.CreatedOn}");
}
```
### Update Key Properties
```csharp
KeyVaultKey key = await client.GetKeyAsync("my-rsa-key");
key.Properties.ExpiresOn = DateTimeOffset.UtcNow.AddYears(2);
key.Properties.Tags["environment"] = "production";
KeyVaultKey updatedKey = await client.UpdateKeyPropertiesAsync(key.Properties);
```
### Delete and Purge Keys
```csharp
// Start delete operation
DeleteKeyOperation operation = await client.StartDeleteKeyAsync("my-rsa-key");
// Wait for deletion to complete (required before purge)
await operation.WaitForCompletionAsync();
Console.WriteLine($"Deleted key scheduled purge date: {operation.Value.ScheduledPurgeDate}");
// Purge immediately (if soft-delete is enabled)
await client.PurgeDeletedKeyAsync("my-rsa-key");
// Or recover deleted key
KeyVaultKey recoveredKey = await client.StartRecoverDeletedKeyAsync("my-rsa-key");
```
### Backup and Restore
```csharp
// Backup key
byte[] backup = await client.BackupKeyAsync("my-rsa-key");
await File.WriteAllBytesAsync("key-backup.bin", backup);
// Restore key
byte[] backupData = await File.ReadAllBytesAsync("key-backup.bin");
KeyVaultKey restoredKey = await client.RestoreKeyBackupAsync(backupData);
```
## Cryptographic Operations
### Get CryptographyClient
```csharp
// From KeyClient
KeyVaultKey key = await client.GetKeyAsync("my-rsa-key");
CryptographyClient cryptoClient = client.GetCryptographyClient(
key.Name,
key.Properties.Version);
// Or create directly with key ID
CryptographyClient cryptoClient = new CryptographyClient(
new Uri("https://myvault.vault.azure.net/keys/my-rsa-key/version"),
new DefaultAzureCredential());
```
### Encrypt and Decrypt
```csharp
byte[] plaintext = Encoding.UTF8.GetBytes("Secret message to encrypt");
// Encrypt
EncryptResult encryptResult = await cryptoClient.EncryptAsync(
EncryptionAlgorithm.RsaOaep256,
plaintext);
Console.WriteLine($"Encrypted: {Convert.ToBase64String(encryptResult.Ciphertext)}");
// Decrypt
DecryptResult decryptResult = await cryptoClient.DecryptAsync(
EncryptionAlgorithm.RsaOaep256,
encryptResult.Ciphertext);
string decrypted = Encoding.UTF8.GetString(decryptResult.Plaintext);
Console.WriteLine($"Decrypted: {decrypted}");
```
### Wrap and Unwrap Keys
```csharp
// Key to wrap (e.g., AES key)
byte[] keyToWrap = new byte[32]; // 256-bit key
RandomNumberGenerator.Fill(keyToWrap);
// Wrap key
WrapResult wrapResult = await cryptoClient.WrapKeyAsync(
KeyWrapAlgorithm.RsaOaep256,
keyToWrap);
// Unwrap key
UnwrapResult unwrapResult = await cryptoClient.UnwrapKeyAsync(
KeyWrapAlgorithm.RsaOaep256,
wrapResult.EncryptedKey);
```
### Sign and Verify
```csharp
// Data to sign
byte[] data = Encoding.UTF8.GetBytes("Data to sign");
// Sign data (computes hash internally)
SignResult signResult = await cryptoClient.SignDataAsync(
SignatureAlgorithm.RS256,
data);
// Verify signature
VerifyResult verifyResult = await cryptoClient.VerifyDataAsync(
SignatureAlgorithm.RS256,
data,
signResult.Signature);
Console.WriteLine($"Signature valid: {verifyResult.IsValid}");
// Or sign pre-computed hash
using var sha256 = SHA256.Create();
byte[] hash = sha256.ComputeHash(data);
SignResult signHashResult = await cryptoClient.SignAsync(
SignatureAlgorithm.RS256,
hash);
```
## Key Resolver
```csharp
using Azure.Security.KeyVault.Keys.Cryptography;
var resolver = new KeyResolver(new DefaultAzureCredential());
// Resolve key by ID to get CryptographyClient
CryptographyClient cryptoClient = await resolver.ResolveAsync(
new Uri("https://myvault.vault.azure.net/keys/my-key/version"));
// Use for encryption
EncryptResult result = await cryptoClient.EncryptAsync(
EncryptionAlgorithm.RsaOaep256,
plaintext);
```
## Key Rotation
```csharp
// Rotate key (creates new version)
KeyVaultKey rotatedKey = await client.RotateKeyAsync("my-rsa-key");
Console.WriteLine($"New version: {rotatedKey.Properties.Version}");
// Get rotation policy
KeyRotationPolicy policy = await client.GetKeyRotationPolicyAsync("my-rsa-key");
// Update rotation policy
policy.ExpiresIn = "P90D"; // 90 days
policy.LifetimeActions.Add(new KeyRotationLifetimeAction
{
Action = KeyRotationPolicyAction.Rotate,
TimeBeforeExpiry = "P30D" // Rotate 30 days before expiry
});
await client.UpdateKeyRotationPolicyAsync("my-rsa-key", policy);
```
## Key Types Reference
| Type | Purpose |
|------|---------|
| `KeyClient` | Key management operations |
| `CryptographyClient` | Cryptographic operations |
| `KeyResolver` | Resolve key ID to CryptographyClient |
| `KeyVaultKey` | Key with cryptographic material |
| `KeyProperties` | Key metadata (no crypto material) |
| `CreateRsaKeyOptions` | RSA key creation options |
| `CreateEcKeyOptions` | EC key creation options |
| `CreateOctKeyOptions` | Symmetric key options |
| `EncryptResult` | Encryption result |
| `DecryptResult` | Decryption result |
| `SignResult` | Signing result |
| `VerifyResult` | Verification result |
| `WrapResult` | Key wrap result |
| `UnwrapResult` | Key unwrap result |
## Algorithms Reference
### Encryption Algorithms
| Algorithm | Key Type | Description |
|-----------|----------|-------------|
| `RsaOaep` | RSA | RSA-OAEP |
| `RsaOaep256` | RSA | RSA-OAEP-256 |
| `Rsa15` | RSA | RSA 1.5 (legacy) |
| `A128Gcm` | Oct | AES-128-GCM |
| `A256Gcm` | Oct | AES-256-GCM |
### Signature Algorithms
| Algorithm | Key Type | Description |
|-----------|----------|-------------|
| `RS256` | RSA | RSASSA-PKCS1-v1_5 SHA-256 |
| `RS384` | RSA | RSASSA-PKCS1-v1_5 SHA-384 |
| `RS512` | RSA | RSASSA-PKCS1-v1_5 SHA-512 |
| `PS256` | RSA | RSASSA-PSS SHA-256 |
| `ES256` | EC | ECDSA P-256 SHA-256 |
| `ES384` | EC | ECDSA P-384 SHA-384 |
| `ES512` | EC | ECDSA P-521 SHA-512 |
### Key Wrap Algorithms
| Algorithm | Key Type | Description |
|-----------|----------|-------------|
| `RsaOaep` | RSA | RSA-OAEP |
| `RsaOaep256` | RSA | RSA-OAEP-256 |
| `A128KW` | Oct | AES-128 Key Wrap |
| `A256KW` | Oct | AES-256 Key Wrap |
## Best Practices
1. **Use Managed Identity** — Prefer `DefaultAzureCredential` over secrets
2. **Enable soft-delete** — Protect against accidental deletion
3. **Use HSM-backed keys** — Set `HardwareProtected = true` for sensitive keys
4. **Implement key rotation** — Use automatic rotation policies
5. **Limit key operations** — Only enable required `KeyOperations`
6. **Set expiration dates** — Always set `ExpiresOn` for keys
7. **Use specific versions** — Pin to versions in production
8. **Cache CryptographyClient** — Reuse for multiple operations
## Error Handling
```csharp
using Azure;
try
{
KeyVaultKey key = await client.GetKeyAsync("my-key");
}
catch (RequestFailedException ex) when (ex.Status == 404)
{
Console.WriteLine("Key not found");
}
catch (RequestFailedException ex) when (ex.Status == 403)
{
Console.WriteLine("Access denied - check RBAC permissions");
}
catch (RequestFailedException ex)
{
Console.WriteLine($"Key Vault error: {ex.Status} - {ex.Message}");
}
```
## Required RBAC Roles
| Role | Permissions |
|------|-------------|
| Key Vault Crypto Officer | Full key management |
| Key Vault Crypto User | Use keys for crypto operations |
| Key Vault Reader | Read key metadata |
## Related SDKs
| SDK | Purpose | Install |
|-----|---------|---------|
| `Azure.Security.KeyVault.Keys` | Keys (this SDK) | `dotnet add package Azure.Security.KeyVault.Keys` |
| `Azure.Security.KeyVault.Secrets` | Secrets | `dotnet add package Azure.Security.KeyVault.Secrets` |
| `Azure.Security.KeyVault.Certificates` | Certificates | `dotnet add package Azure.Security.KeyVault.Certificates` |
| `Azure.Identity` | Authentication | `dotnet add package Azure.Identity` |
## Reference Links
| Resource | URL |
|----------|-----|
| NuGet Package | https://www.nuget.org/packages/Azure.Security.KeyVault.Keys |
| API Reference | https://learn.microsoft.com/dotnet/api/azure.security.keyvault.keys |
| Quickstart | https://learn.microsoft.com/azure/key-vault/keys/quick-create-net |
| GitHub Source | https://github.com/Azure/azure-sdk-for-net/tree/main/sdk/keyvault/Azure.Security.KeyVault.Keys |