kms: add IAM methods

These methods are not auto-generated because they are not present in the .proto file.
We use the same workaround as we do for pubsub.

Change-Id: I5a0ae98a534c2aae1c45574f75e395e964d245d1
Reviewed-on: https://code-review.googlesource.com/c/34990
Reviewed-by: kokoro <noreply+kokoro@google.com>
Reviewed-by: Jean de Klerk <deklerk@google.com>
diff --git a/kms/apiv1/iam.go b/kms/apiv1/iam.go
new file mode 100644
index 0000000..8c572a9
--- /dev/null
+++ b/kms/apiv1/iam.go
@@ -0,0 +1,30 @@
+// Copyright 2018 Google LLC
+//
+// Licensed under the Apache License, Version 2.0 (the "License");
+// you may not use this file except in compliance with the License.
+// You may obtain a copy of the License at
+//
+//     https://www.apache.org/licenses/LICENSE-2.0
+//
+// Unless required by applicable law or agreed to in writing, software
+// distributed under the License is distributed on an "AS IS" BASIS,
+// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+// See the License for the specific language governing permissions and
+// limitations under the License.
+
+package kms
+
+import (
+	"cloud.google.com/go/iam"
+	kmspb "google.golang.org/genproto/googleapis/cloud/kms/v1"
+)
+
+// KeyRingIAM returns a handle to inspect and change permissions of a KeyRing.
+func (c *KeyManagementClient) KeyRingIAM(keyRing *kmspb.KeyRing) *iam.Handle {
+	return iam.InternalNewHandle(c.Connection(), keyRing.Name)
+}
+
+// CryptoKeyIAM returns a handle to inspect and change permissions of a CryptoKey.
+func (c *KeyManagementClient) CryptoKeyIAM(cryptoKey *kmspb.CryptoKey) *iam.Handle {
+	return iam.InternalNewHandle(c.Connection(), cryptoKey.Name)
+}