List
Syntax
./nnl-mgmt.sh ruleset list [-name <ruleset-name> -tenantid <tenantid>]Parameter | Description |
|---|---|
tenantid | Optional. Adaptive Rulesets are listed for this tenant ID. Default value is default |
name | Optional. Name of the ruleset to be listed. By default, the system lists all available rulesets for the specified tenant. |
Description
Lists rulesets for the given tenant. You can also see whether the ruleset is in Active or Draft status.
Example
./nnl-mgmt.sh ruleset list -name "testRuleset" -tenantid defaultImport
Syntax
./nnl-mgmt.sh ruleset import -file <ruleset-file> [-overwrite <yes|no> ‑include‑metadata <yes|no> ‑tenantid <tenantid>]Parameter | Description |
|---|---|
file | Mandatory. Name of a file to import from the current directory. This file can be either a JSON file or ZIP file, for specifics, see Description below. If you don’t provide a file name, the command fails. |
tenantid | Optional. Rulesets are imported into this tenant. Default value is default. |
overwrite | Optional. Specifies whether or not the system overwrites an existing ruleset and its dependent objects that have the same name. The value is one of the following:
|
include-metadata | Optional. Specifies whether or not the system imports authenticator metadata. Applies when the ZIP file contains ruleset(s) and authenticator metadata files.
|
Description
This command imports Adaptive Rulesets from the specified import file into the designated tenant. All imported rulesets have a draft status. The import file can either be a JSON or ZIP file. A JSON file contains only Adaptive Rulesets. A ZIP file contains Adaptive Rulesets, the objects that the rulesets depend on, and, optionally, authenticator metadata used by the rulesets.
Dependencies for an Adaptive Ruleset include FIDO policies, authenticator groups, country lists, device model lists, geofence lists, IP address lists, and WiFi network lists used by any rules contained in the ruleset.
If overwrite is yes, then existing rulesets, FIDO policies, lists, and authenticator groups with the same name are overwritten. Overwrite handles objects differently depending on their type and status, as shown in the table below.
Object | Status of Existing Object | Result |
|---|---|---|
Ruleset | draft | The system overwrites the existing ruleset with the one from the file. |
active | The system creates a new draft ruleset with the same name. The existing active ruleset remains. | |
FIDO Policy | draft | The system overwrites the existing FIDO policy with the one from the file and changes its status to active. All rulesets, whether active or draft, must use active FIDO policies. |
active | The system overwrites the existing FIDO policy with the one from the file and changes its status to active. | |
Lists | N/A | The system overwrites the existing list with the one from the file. This is true even if the list is being used by a different active ruleset. |
Authenticator Groups | N/A | The system overwrites the existing authenticator group with the one from the file. This is true even if the authenticator group is being used by a different active FIDO Policy. |
You can optionally set include-metadata to yes in order to import authenticator metadata. Use this option in limited situations, such as you intend to use authenticator metadata that was only in a development deployment in a production deployment. Remember, authenticator metadata is accessible to all tenants in an S3 Suite installation and overwriting metadata could have unintended consequences.
This command fails in the following scenarios:
A draft ruleset with the same name exists and you specify no for overwrite.
The ruleset file is larger than 512 KB, the default maximum size. You can change this size by updating the nnl.rulesets.file.size.kb property for the Admin tenant, as shown below.
Change the maximum size allowed for an imported ruleset file to 1024 KB:
./nnl-mgmt.sh properties set -name nnl.rulesets.file.size.kb -value 1024 ‑tenantid AdminExamples
Import rulesets from a JSON file into the finance tenant:
./nnl-mgmt.sh ruleset import -file transaction-ruleset.json -overwrite yes ‑tenantid financeImport rulesets, dependencies, and authenticator metadata from a ZIP file into the finance tenant:
./nnl-mgmt.sh ruleset import -file transaction-ruleset.zip -overwrite yes ‑include‑metadata yes ‑tenantid financeImport rulesets and dependencies, but not the authenticator metadata, from a ZIP file into the finance tenant:
./nnl-mgmt.sh ruleset import -file transaction-ruleset.zip -overwrite yes ‑include‑metadata no ‑tenantid financeExport
Syntax
./nnl-mgmt.sh ruleset export -name <ruleset-name> [-dir <ruleset‑dir> | -file <file‑path>] [‑with‑dependencies <yes|no> ‑include‑metadata <yes|no> ‑tenantid <tenantid>]Parameter | Description |
|---|---|
name | Mandatory. Name of an active Adaptive Ruleset to export. If you don’t provide a name, the command fails. |
dir | Optional. Name of the destination directory where the system writes the export file. By default, the file is written to the current directory. |
file | Optional. A file path. The system exports the Adaptive Ruleset and, if specified, the ruleset's dependencies and its associated authenticator metadata to the file path. The file cannot exist. |
tenantid | Optional. An Adaptive Ruleset defined in this tenant ID is exported. Default value is default |
with-dependencies | Optional. Indicates if the system should export the ruleset’s dependencies, such as lists, authenticator groups, and FIDO policies.
|
include-metadata | Optional. Only allowed if with-dependencies is yes. Indicates if the system should export authenticator metadata referenced in FIDO policies used by rules contained in the Adaptive Ruleset.
|
Description
Exports the specified ruleset for the given tenant. If only a ruleset is exported, the system creates a JSON file. If the ruleset’s dependencies and authenticator metadata are included, the system creates a ZIP file.
You either specify a directory or file path where the system exports the objects but not both. The file path already includes the directory. If you only specify dir, then the system generates the file name.
Dependencies for an Adaptive Ruleset include FIDO policies, authenticator groups, country lists, device model lists, geofence lists, IP address lists, and WiFi network lists used by any rules contained in the ruleset.
Examples
Export an Adaptive Ruleset without dependencies (results in a JSON file).
./nnl-mgmt.sh ruleset export -name FIDORuleset -dir /home/zsmith -tenantid NorthAmericaExport an Adaptive Ruleset without dependencies (results in a JSON file) into the specified file.
./nnl-mgmt.sh ruleset export -name FIDORuleset -file /home/zsmith/my_ruleset.json ‑tenantid NorthAmericaExport an Adaptive Ruleset with dependencies (results in a ZIP file).
./nnl-mgmt.sh ruleset export -name FIDORuleset -dir /home/zsmith ‑with‑dependencies yes ‑include‑metadata no -tenantid EuropeOr
./nnl-mgmt.sh ruleset export -name FIDORuleset -dir /home/zsmith ‑with‑dependencies yes -tenantid EuropeExport an Adaptive Ruleset, dependencies, and authenticator metadata (results in a ZIP file).
./nnl-mgmt.sh ruleset export -name FIDORuleset -dir /home/zsmith ‑with‑dependencies yes ‑include‑metadata yes -tenantid AsiaActivate
Syntax
./nnl-mgmt.sh ruleset activate -name <ruleset-name> [-tenantid <tenantid>]Parameter | Description |
|---|---|
name | Mandatory. The name of the Adaptive Ruleset to activate. If you don’t provide a file name, the command fails. |
tenantid | Optional. Activates the specified Adaptive Ruleset defined for this tenant ID. Default value is default. |
Description
Activates an Adaptive Ruleset that is in draft status for the given tenant. If the ruleset is already activated, the command returns an error. An Adaptive Ruleset must be activated in order to be used.
Example
./nnl-mgmt.sh ruleset activate -name "testRuleset" -tenantid financeDelete
Syntax
./nnl-mgmt.sh ruleset delete -name <ruleset-name> -status <status> [‑tenantid <tenantid>]Parameter | Description |
|---|---|
name | Mandatory. Name of the ruleset to delete. If you don’t provide a name, the command fails. |
status | Mandatory. Status of the ruleset file to delete. Status can be draft or active. |
tenantid | Optional. The system deletes the ruleset specific to this tenant ID. Default value is default. |
Description
Deletes a ruleset for the given tenant.
Example
./nnl-mgmt.sh ruleset delete -name testRuleset -tenantid finance -status active
./nnl-mgmt.sh ruleset delete -name testRuleset -tenantid finance -status draft