Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Adaptive Ruleset Commands

Prev Next

List

Syntax

./nnl-mgmt.sh ruleset list [-name <ruleset-name> -tenantid <tenantid>]

Parameter

Description

tenantid

Optional. Adaptive Rulesets are listed for this tenant ID. Default value is default

name

Optional. Name of the ruleset to be listed. By default, the system lists all available rulesets for the specified tenant.

Description

Lists rulesets for the given tenant. You can also see whether the ruleset is in Active or Draft status.

Example

./nnl-mgmt.sh ruleset list -name "testRuleset" -tenantid default

Import

Syntax

./nnl-mgmt.sh ruleset import -file <ruleset-file> [-overwrite <yes|no> ‑include‑metadata <yes|no> ‑tenantid <tenantid>]

Parameter

Description

file

Mandatory. Name of a file to import from the current directory.

This file can be either a JSON file or ZIP file, for specifics, see Description below. If you don’t provide a file name, the command fails.

tenantid

Optional. Rulesets are imported into this tenant. Default value is default.

overwrite

Optional. Specifies whether or not the system overwrites an existing ruleset and its dependent objects that have the same name. The value is one of the following:

  • Yes: The system overwrites objects with the same name. See Description below for details.

  • No (default): The system does not overwrite an object with the same name.

include-metadata

Optional. Specifies whether or not the system imports authenticator metadata. Applies when the ZIP file contains ruleset(s) and authenticator metadata files.

  • Yes: The system imports and overwrites authenticator metadata.

  • No (default): The system doesn’t import authenticator metadata.

Description

This command imports Adaptive Rulesets from the specified import file into the designated tenant. All imported rulesets have a draft status. The import file can either be a JSON or ZIP file. A JSON file contains only Adaptive Rulesets. A ZIP file contains Adaptive Rulesets, the objects that the rulesets depend on, and, optionally, authenticator metadata used by the rulesets.

Dependencies for an Adaptive Ruleset include FIDO policies, authenticator groups, country lists, device model lists, geofence lists, IP address lists, and WiFi network lists used by any rules contained in the ruleset.

If overwrite is yes, then existing rulesets, FIDO policies, lists, and authenticator groups with the same name are overwritten. Overwrite handles objects differently depending on their type and status, as shown in the table below.

Object

Status of Existing Object

Result

Ruleset

draft

The system overwrites the existing ruleset with the one from the file.

active

The system creates a new draft ruleset with the same name. The existing active ruleset remains.

FIDO Policy

draft

The system overwrites the existing FIDO policy with the one from the file and changes its status to active. All rulesets, whether active or draft, must use active FIDO policies.

active

The system overwrites the existing FIDO policy with the one from the file and changes its status to active.

Lists

N/A

The system overwrites the existing list with the one from the file. This is true even if the list is being used by a different active ruleset.

Authenticator Groups

N/A

The system overwrites the existing authenticator group with the one from the file. This is true even if the authenticator group is being used by a different active FIDO Policy.

You can optionally set include-metadata to yes in order to import authenticator metadata. Use this option in limited situations, such as you intend to use authenticator metadata that was only in a development deployment in a production deployment. Remember, authenticator metadata is accessible to all tenants in an S3 Suite installation and overwriting metadata could have unintended consequences.

This command fails in the following scenarios:

  • A draft ruleset with the same name exists and you specify no for overwrite.

  • The ruleset file is larger than 512 KB, the default maximum size. You can change this size by updating the nnl.rulesets.file.size.kb property for the Admin tenant, as shown below.

Change the maximum size allowed for an imported ruleset file to 1024 KB:

./nnl-mgmt.sh properties set -name nnl.rulesets.file.size.kb -value 1024 ‑tenantid Admin

Examples

Import rulesets from a JSON file into the finance tenant:

./nnl-mgmt.sh ruleset import -file transaction-ruleset.json -overwrite yes ‑tenantid finance

Import rulesets, dependencies, and authenticator metadata from a ZIP file into the finance tenant:

./nnl-mgmt.sh ruleset import -file transaction-ruleset.zip -overwrite yes ‑include‑metadata yes ‑tenantid finance

Import rulesets and dependencies, but not the authenticator metadata, from a ZIP file into the finance tenant:

./nnl-mgmt.sh ruleset import -file transaction-ruleset.zip -overwrite yes ‑include‑metadata no ‑tenantid finance

Export

Syntax

./nnl-mgmt.sh ruleset export -name <ruleset-name> [-dir <ruleset‑dir> | -file <file‑path>] [‑with‑dependencies <yes|no> ‑include‑metadata <yes|no> ‑tenantid <tenantid>]

Parameter

Description

name

Mandatory. Name of an active Adaptive Ruleset to export. If you don’t provide a name, the command fails.

dir

Optional. Name of the destination directory where the system writes the export file. By default, the file is written to the current directory.

file

Optional. A file path. The system exports the Adaptive Ruleset and, if specified, the ruleset's dependencies and its associated authenticator metadata to the file path. The file cannot exist.

tenantid

Optional. An Adaptive Ruleset defined in this tenant ID is exported. Default value is default

with-dependencies

Optional. Indicates if the system should export the ruleset’s dependencies, such as lists, authenticator groups, and FIDO policies.

  • Yes: The system exports the ruleset’s dependencies.

  • No (default): The system does not export the ruleset’s dependencies.

include-metadata

Optional. Only allowed if with-dependencies is yes. Indicates if the system should export authenticator metadata referenced in FIDO policies used by rules contained in the Adaptive Ruleset.

  • Yes: The system exports all authenticator metadata referenced by FIDO policies used in the ruleset.

  • No (default): The system does not export authenticator metadata.

Description

Exports the specified ruleset for the given tenant. If only a ruleset is exported, the system creates a JSON file. If the ruleset’s dependencies and authenticator metadata are included, the system creates a ZIP file.

You either specify a directory or file path where the system exports the objects but not both. The file path already includes the directory. If you only specify dir, then the system generates the file name.

Dependencies for an Adaptive Ruleset include FIDO policies, authenticator groups, country lists, device model lists, geofence lists, IP address lists, and WiFi network lists used by any rules contained in the ruleset.

Examples

Export an Adaptive Ruleset without dependencies (results in a JSON file).

./nnl-mgmt.sh ruleset export -name FIDORuleset -dir /home/zsmith -tenantid NorthAmerica

Export an Adaptive Ruleset without dependencies (results in a JSON file) into the specified file.

./nnl-mgmt.sh ruleset export -name FIDORuleset -file /home/zsmith/my_ruleset.json ‑tenantid NorthAmerica

Export an Adaptive Ruleset with dependencies (results in a ZIP file).

./nnl-mgmt.sh ruleset export -name FIDORuleset -dir /home/zsmith ‑with‑dependencies yes ‑include‑metadata no -tenantid Europe

Or

./nnl-mgmt.sh ruleset export -name FIDORuleset -dir /home/zsmith ‑with‑dependencies yes -tenantid Europe

Export an Adaptive Ruleset, dependencies, and authenticator metadata (results in a ZIP file).

./nnl-mgmt.sh ruleset export -name FIDORuleset -dir /home/zsmith ‑with‑dependencies yes ‑include‑metadata yes -tenantid Asia

Activate

Syntax

./nnl-mgmt.sh ruleset activate -name <ruleset-name> [-tenantid <tenantid>]

Parameter

Description

name

Mandatory. The name of the Adaptive Ruleset to activate. If you don’t provide a file name, the command fails.

tenantid

Optional. Activates the specified Adaptive Ruleset defined for this tenant ID. Default value is default.

Description

Activates an Adaptive Ruleset that is in draft status for the given tenant. If the ruleset is already activated, the command returns an error. An Adaptive Ruleset must be activated in order to be used.

Example

./nnl-mgmt.sh ruleset activate -name "testRuleset" -tenantid finance

Delete

Syntax

./nnl-mgmt.sh ruleset delete -name <ruleset-name> -status <status> [‑tenantid <tenantid>]

Parameter

Description

name

Mandatory. Name of the ruleset to delete. If you don’t provide a name, the command fails.

status

Mandatory. Status of the ruleset file to delete. Status can be draft or active.

tenantid

Optional. The system deletes the ruleset specific to this tenant ID. Default value is default.

Description

Deletes a ruleset for the given tenant.

Example

./nnl-mgmt.sh ruleset delete -name testRuleset -tenantid finance -status active
./nnl-mgmt.sh ruleset delete -name testRuleset -tenantid finance -status draft