A populated MediaAttachment with ciphertextSha256,
plaintextSha256, nonce, mediaType, and filename set, and
locators empty. The caller adds one or more MediaLocator entries
after uploading encrypted, then serializes the attachment with
encodeMediaImetaTag.
The encrypted blob. Upload this to a blob store; SHA256(encrypted) (also
available as attachment.ciphertextSha256) is the preferred content id.
Result of encryptMediaFile.