Table of Contents
A low-level client representing AWS Signer:
client = session.create_client('signer')
These are the available methods:
Check if an operation can be paginated.
Changes the state of an ACTIVE signing profile to CANCELED . A canceled profile is still viewable with the ListSigningProfiles operation, but it cannot perform new signing jobs, and is deleted two years after cancelation.
See also: AWS API Documentation
Request Syntax
response = client.cancel_signing_profile(
profileName='string'
)
[REQUIRED]
The name of the signing profile to be canceled.
Returns information about a specific code signing job. You specify the job by using the jobId value that is returned by the StartSigningJob operation.
See also: AWS API Documentation
Request Syntax
response = client.describe_signing_job(
jobId='string'
)
[REQUIRED]
The ID of the signing job on input.
{
'jobId': 'string',
'source': {
's3': {
'bucketName': 'string',
'key': 'string',
'version': 'string'
}
},
'signingMaterial': {
'certificateArn': 'string'
},
'platformId': 'string',
'profileName': 'string',
'overrides': {
'signingConfiguration': {
'encryptionAlgorithm': 'RSA'|'ECDSA',
'hashAlgorithm': 'SHA1'|'SHA256'
}
},
'signingParameters': {
'string': 'string'
},
'createdAt': datetime(2015, 1, 1),
'completedAt': datetime(2015, 1, 1),
'requestedBy': 'string',
'status': 'InProgress'|'Failed'|'Succeeded',
'statusReason': 'string',
'signedObject': {
's3': {
'bucketName': 'string',
'key': 'string'
}
}
}
Response Structure
The ID of the signing job on output.
The object that contains the name of your S3 bucket or your raw code.
The S3Source object.
Name of the S3 bucket.
Key name of the bucket object that contains your unsigned code.
Version of your source image in your version enabled S3 bucket.
Amazon Resource Name (ARN) of your code signing certificate.
The Amazon Resource Name (ARN) of the certificates that is used to sign your code.
The microcontroller platform to which your signed code image will be distributed.
The name of the profile that initiated the signing operation.
A list of any overrides that were applied to the signing operation.
A signing configuration that overrides the default encryption or hash algorithm of a signing job.
A specified override of the default encryption algorithm that is used in an AWS Signer job.
A specified override of the default hash algorithm that is used in an AWS Signer job.
Map of user-assigned key-value pairs used during signing. These values contain any information that you specified for use in your signing job.
Date and time that the signing job was created.
Date and time that the signing job was completed.
The IAM principal that requested the signing job.
Status of the signing job.
String value that contains the status reason.
Name of the S3 bucket where the signed code image is saved by AWS Signer.
The S3SignedObject .
Name of the S3 bucket.
Key name that uniquely identifies a signed code image in your bucket.
Generate a presigned url given a client, its method, and arguments
The presigned url
Create a paginator for an operation.
Returns information on a specific signing platform.
See also: AWS API Documentation
Request Syntax
response = client.get_signing_platform(
platformId='string'
)
[REQUIRED]
The ID of the target signing platform.
{
'platformId': 'string',
'displayName': 'string',
'partner': 'string',
'target': 'string',
'category': 'AWSIoT',
'signingConfiguration': {
'encryptionAlgorithmOptions': {
'allowedValues': [
'RSA'|'ECDSA',
],
'defaultValue': 'RSA'|'ECDSA'
},
'hashAlgorithmOptions': {
'allowedValues': [
'SHA1'|'SHA256',
],
'defaultValue': 'SHA1'|'SHA256'
}
},
'signingImageFormat': {
'supportedFormats': [
'JSON',
],
'defaultFormat': 'JSON'
},
'maxSizeInMB': 123
}
Response Structure
The ID of the target signing platform.
The display name of the target signing platform.
A list of partner entities that use the target signing platform.
The validation template that is used by the target signing platform.
The category type of the target signing platform.
A list of configurations applied to the target platform at signing.
The encryption algorithm options that are available for an AWS Signer job.
The set of accepted encryption algorithms that are allowed in an AWS Signer job.
The default encryption algorithm that is used by an AWS Signer job.
The hash algorithm options that are available for an AWS Signer job.
The set of accepted hash algorithms allowed in an AWS Signer job.
The default hash algorithm that is used in an AWS Signer job.
The format of the target platform's signing image.
The supported formats of an AWS Signer signing image.
The default format of an AWS Signer signing image.
The maximum size (in MB) of the payload that can be signed by the target platform.
Returns information on a specific signing profile.
See also: AWS API Documentation
Request Syntax
response = client.get_signing_profile(
profileName='string'
)
[REQUIRED]
The name of the target signing profile.
{
'profileName': 'string',
'signingMaterial': {
'certificateArn': 'string'
},
'platformId': 'string',
'overrides': {
'signingConfiguration': {
'encryptionAlgorithm': 'RSA'|'ECDSA',
'hashAlgorithm': 'SHA1'|'SHA256'
}
},
'signingParameters': {
'string': 'string'
},
'status': 'Active'|'Canceled'
}
Response Structure
The name of the target signing profile.
The ARN of the certificate that the target profile uses for signing operations.
The Amazon Resource Name (ARN) of the certificates that is used to sign your code.
The ID of the platform that is used by the target signing profile.
A list of overrides applied by the target signing profile for signing operations.
A signing configuration that overrides the default encryption or hash algorithm of a signing job.
A specified override of the default encryption algorithm that is used in an AWS Signer job.
A specified override of the default hash algorithm that is used in an AWS Signer job.
A map of key-value pairs for signing operations that is attached to the target signing profile.
The status of the target signing profile.
Returns an object that can wait for some condition.
Lists all your signing jobs. You can use the maxResults parameter to limit the number of signing jobs that are returned in the response. If additional jobs remain to be listed, AWS Signer returns a nextToken value. Use this value in subsequent calls to ListSigningJobs to fetch the remaining values. You can continue calling ListSigningJobs with your maxResults parameter and with new values that AWS Signer returns in the nextToken parameter until all of your signing jobs have been returned.
See also: AWS API Documentation
Request Syntax
response = client.list_signing_jobs(
status='InProgress'|'Failed'|'Succeeded',
platformId='string',
requestedBy='string',
maxResults=123,
nextToken='string'
)
dict
Response Syntax
{
'jobs': [
{
'jobId': 'string',
'source': {
's3': {
'bucketName': 'string',
'key': 'string',
'version': 'string'
}
},
'signedObject': {
's3': {
'bucketName': 'string',
'key': 'string'
}
},
'signingMaterial': {
'certificateArn': 'string'
},
'createdAt': datetime(2015, 1, 1),
'status': 'InProgress'|'Failed'|'Succeeded'
},
],
'nextToken': 'string'
}
Response Structure
(dict) --
jobs (list) --
A list of your signing jobs.
(dict) --
Contains information about a signing job.
jobId (string) --
The ID of the signing job.
source (dict) --
A Source that contains information about a signing job's code image source.
s3 (dict) --
The S3Source object.
bucketName (string) --
Name of the S3 bucket.
key (string) --
Key name of the bucket object that contains your unsigned code.
version (string) --
Version of your source image in your version enabled S3 bucket.
signedObject (dict) --
A SignedObject structure that contains information about a signing job's signed code image.
s3 (dict) --
The S3SignedObject .
bucketName (string) --
Name of the S3 bucket.
key (string) --
Key name that uniquely identifies a signed code image in your bucket.
signingMaterial (dict) --
A SigningMaterial object that contains the Amazon Resource Name (ARN) of the certificate used for the signing job.
certificateArn (string) --
The Amazon Resource Name (ARN) of the certificates that is used to sign your code.
createdAt (datetime) --
The date and time that the signing job was created.
status (string) --
The status of the signing job.
nextToken (string) --
String for specifying the next set of paginated results.
Lists all signing platforms available in AWS Signer that match the request parameters. If additional jobs remain to be listed, AWS Signer returns a nextToken value. Use this value in subsequent calls to ListSigningJobs to fetch the remaining values. You can continue calling ListSigningJobs with your maxResults parameter and with new values that AWS Signer returns in the nextToken parameter until all of your signing jobs have been returned.
See also: AWS API Documentation
Request Syntax
response = client.list_signing_platforms(
category='string',
partner='string',
target='string',
maxResults=123,
nextToken='string'
)
dict
Response Syntax
{
'platforms': [
{
'platformId': 'string',
'displayName': 'string',
'partner': 'string',
'target': 'string',
'category': 'AWSIoT',
'signingConfiguration': {
'encryptionAlgorithmOptions': {
'allowedValues': [
'RSA'|'ECDSA',
],
'defaultValue': 'RSA'|'ECDSA'
},
'hashAlgorithmOptions': {
'allowedValues': [
'SHA1'|'SHA256',
],
'defaultValue': 'SHA1'|'SHA256'
}
},
'signingImageFormat': {
'supportedFormats': [
'JSON',
],
'defaultFormat': 'JSON'
},
'maxSizeInMB': 123
},
],
'nextToken': 'string'
}
Response Structure
(dict) --
platforms (list) --
A list of all platforms that match the request parameters.
(dict) --
Contains information about the signing configurations and parameters that is used to perform an AWS Signer job.
platformId (string) --
The ID of an AWS Signer platform.
displayName (string) --
The display name of an AWS Signer platform.
partner (string) --
Any partner entities linked to an AWS Signer platform.
target (string) --
The types of targets that can be signed by an AWS Signer platform.
category (string) --
The category of an AWS Signer platform.
signingConfiguration (dict) --
The configuration of an AWS Signer platform. This includes the designated hash algorithm and encryption algorithm of a signing platform.
encryptionAlgorithmOptions (dict) --
The encryption algorithm options that are available for an AWS Signer job.
allowedValues (list) --
The set of accepted encryption algorithms that are allowed in an AWS Signer job.
defaultValue (string) --
The default encryption algorithm that is used by an AWS Signer job.
hashAlgorithmOptions (dict) --
The hash algorithm options that are available for an AWS Signer job.
allowedValues (list) --
The set of accepted hash algorithms allowed in an AWS Signer job.
defaultValue (string) --
The default hash algorithm that is used in an AWS Signer job.
signingImageFormat (dict) --
The signing image format that is used by an AWS Signer platform.
supportedFormats (list) --
The supported formats of an AWS Signer signing image.
defaultFormat (string) --
The default format of an AWS Signer signing image.
maxSizeInMB (integer) --
The maximum size (in MB) of code that can be signed by a AWS Signer platform.
nextToken (string) --
Value for specifying the next set of paginated results to return.
Lists all available signing profiles in your AWS account. Returns only profiles with an ACTIVE status unless the includeCanceled request field is set to true . If additional jobs remain to be listed, AWS Signer returns a nextToken value. Use this value in subsequent calls to ListSigningJobs to fetch the remaining values. You can continue calling ListSigningJobs with your maxResults parameter and with new values that AWS Signer returns in the nextToken parameter until all of your signing jobs have been returned.
See also: AWS API Documentation
Request Syntax
response = client.list_signing_profiles(
includeCanceled=True|False,
maxResults=123,
nextToken='string'
)
dict
Response Syntax
{
'profiles': [
{
'profileName': 'string',
'signingMaterial': {
'certificateArn': 'string'
},
'platformId': 'string',
'signingParameters': {
'string': 'string'
},
'status': 'Active'|'Canceled'
},
],
'nextToken': 'string'
}
Response Structure
(dict) --
profiles (list) --
A list of profiles that are available in the AWS account. This includes profiles with the status of CANCELED if the includeCanceled parameter is set to true .
(dict) --
Contains information about the ACM certificates and AWS Signer configuration parameters that can be used by a given AWS Signer user.
profileName (string) --
The name of the AWS Signer profile.
signingMaterial (dict) --
The ACM certificate that is available for use by a signing profile.
certificateArn (string) --
The Amazon Resource Name (ARN) of the certificates that is used to sign your code.
platformId (string) --
The ID of a platform that is available for use by a signing profile.
signingParameters (dict) --
The parameters that are available for use by an AWS Signer user.
status (string) --
The status of an AWS Signer profile.
nextToken (string) --
Value for specifying the next set of paginated results to return.
Creates a signing profile. A signing profile is an AWS Signer template that can be used to carry out a pre-defined signing job. For more information, see http://docs.aws.amazon.com/signer/latest/developerguide/gs-profile.html
See also: AWS API Documentation
Request Syntax
response = client.put_signing_profile(
profileName='string',
signingMaterial={
'certificateArn': 'string'
},
platformId='string',
overrides={
'signingConfiguration': {
'encryptionAlgorithm': 'RSA'|'ECDSA',
'hashAlgorithm': 'SHA1'|'SHA256'
}
},
signingParameters={
'string': 'string'
}
)
[REQUIRED]
The name of the signing profile to be created.
[REQUIRED]
The AWS Certificate Manager certificate that will be used to sign code with the new signing profile.
The Amazon Resource Name (ARN) of the certificates that is used to sign your code.
[REQUIRED]
The ID of the signing profile to be created.
A subfield of platform . This specifies any different configuration options that you want to apply to the chosen platform (such as a different hash-algorithm or signing-algorithm ).
A signing configuration that overrides the default encryption or hash algorithm of a signing job.
A specified override of the default encryption algorithm that is used in an AWS Signer job.
A specified override of the default hash algorithm that is used in an AWS Signer job.
Map of key-value pairs for signing. These can include any information that you want to use during signing.
dict
Response Syntax
{
'arn': 'string'
}
Response Structure
(dict) --
arn (string) --
The Amazon Resource Name (ARN) of the signing profile created.
Initiates a signing job to be performed on the code provided. Signing jobs are viewable by the ListSigningJobs operation for two years after they are performed. Note the following requirements:
You can call the DescribeSigningJob and the ListSigningJobs actions after you call StartSigningJob .
For a Java example that shows how to use this action, see http://docs.aws.amazon.com/acm/latest/userguide/
See also: AWS API Documentation
Request Syntax
response = client.start_signing_job(
source={
's3': {
'bucketName': 'string',
'key': 'string',
'version': 'string'
}
},
destination={
's3': {
'bucketName': 'string',
'prefix': 'string'
}
},
profileName='string',
clientRequestToken='string'
)
[REQUIRED]
The S3 bucket that contains the object to sign or a BLOB that contains your raw code.
The S3Source object.
Name of the S3 bucket.
Key name of the bucket object that contains your unsigned code.
Version of your source image in your version enabled S3 bucket.
[REQUIRED]
The S3 bucket in which to save your signed object. The destination contains the name of your bucket and an optional prefix.
The S3Destination object.
Name of the S3 bucket.
An Amazon S3 prefix that you can use to limit responses to those that begin with the specified prefix.
[REQUIRED]
String that identifies the signing request. All calls after the first that use this token return the same response as the first call.
This field is autopopulated if not provided.
dict
Response Syntax
{
'jobId': 'string'
}
Response Structure
(dict) --
jobId (string) --
The ID of your signing job.
The available paginators are:
The available waiters are:
waiter = client.get_waiter('successful_signing_job')
Polls signer.Client.describe_signing_job() every 20 seconds until a successful state is reached. An error is returned after 25 failed checks.
See also: AWS API Documentation
Request Syntax
waiter.wait(
jobId='string',
WaiterConfig={
'Delay': 123,
'MaxAttempts': 123
}
)
[REQUIRED]
The ID of the signing job on input.
A dictionary that provides parameters to control waiting behavior.
The amount of time in seconds to wait between attempts. Default: 20
The maximum number of attempts to be made. Default: 25
None