Download from the Metadata Service
Syntax
./nnl-mgmt.sh auth_metadata download -dir <directory> [-disablecrl <yes|no>]Parameter | Description |
|---|---|
dir | Mandatory. Directory where the metadata is downloaded. |
disablecrl | Optional. yes disables the check on the Certificate Revocation List. If not provided, the check on CRL is enabled. |
Description
Use this command to download and process all MDS3-compatible authenticator metadata to generate 3 reports. The download command requires an outgoing connection to the FIDO Alliance Metadata Service from the computer where it runs.
The command downloads metadata from the FIDO Alliance Metadata Service and creates the directory structure shown below. If the directory you supply contains metadata files and reports from a previous execution of this command, then they are overwritten.
|
|---|
Each metadata JSON file is located in the protocol directory associated with that authenticator. For example, the file for a Windows Hello hardware authenticator, a FIDO2 authenticator, can be found in the fido2 directory.
The reports are written to the supplied directory. They contain the status and information about each authenticator in different formats. Check nnl-mds3-summary-report.txt for any flagged authenticators. See the FIDO Alliance Metadata Service for more information.
Examples
./nnl-mgmt.sh auth_metadata download -dir project_metadata
startcode./nnl-mgmt.sh auth_metadata download -dir project_metadata -disablecrl yesProcess Previously Downloaded Metadata
Syntax
./nnl-mgmt.sh auth_metadata process -file <mds3 metadata blob file> -dir <dir-path> [-disablecrl <yes|no>]Parameter | Description |
|---|---|
dir | Mandatory. Directory where the metadata is placed after extraction from blob.jwt file. |
file | Mandatory. Absolute path to MDS3 metadata blob .jwt file that was previously downloaded from a metadata service. |
disablecrl | Optional. yes disables the check on the Certificate Revocation List. If not provided, the check on CRL is enabled. |
Description
Use this command to process MDS3-compatible authenticator metadata that has already been downloaded. It extracts individual metadata and places it into the directory depending on its protocol, and generates the same 3 reports as the download command generates. Output from the process command is the same as the output from the download command.
Example
./nnl-mgmt.sh auth_metadata process -file mds3_metadata_blob_file -dir project_metadataImport
Syntax
./nnl-mgmt.sh auth_metadata import (-dir <auth-spec-dir>|-file <auth‑spec‑file>)You must supply either the directory name or the file name in your request, otherwise this command fails.
Parameter | Description |
|---|---|
dir | Name of the directory which contains the metadata JSON files. You must specify the directory if you do not provide a file name. |
file | Name of the JSON file. The auth metadata from the JSON file is loaded into the database. You must specify the file name if you do not provide a directory. |
Description
Use this command to import or update authenticator-specific metadata.
The authenticator is imported or updated from a directory or JSON file. The -dir option processes all files with a .json extension within the specified directory.
Before updating the Server with new metadata statements, validate them first using the FIDO Conformance Tool at https://fidoalliance.org/conformance/.
The maximum size of the authenticator metadata file that can be imported is 128 KB. This default maximum size can be changed by setting the nnl.list.auth.metadata.file.size.kb property for the Admin tenant.
Examples
./nnl-mgmt.sh auth_metadata import -dir test_directory
./nnl-mgmt.sh auth_metadata import -file test_file.jsonChange the maximum size of the authenticator metadata file to 20KB:
./nnl-mgmt.sh properties set -name nnl.list.auth.metadata.file.size.kb -value 20 ‑tenantid AdminExport
Syntax
./nnl-mgmt.sh auth_metadata export (-aaid <aaid>|-aaguid <aaguid>|-acki <acki>) -file <path-to-file>Parameter | Description |
|---|---|
aaid OR aaguid OR acki | Mandatory. Authenticator Metadata ID to be exported. One of
|
file | Mandatory. The system exports the authenticator metadata to this file path. If you don’t provide the file path, the command fails. |
Description
Exports authenticator-specific metadata to the specified JSON file.
Example
./nnl-mgmt.sh auth_metadata export -aaid <aaid> -file /home/zsmith/exported_metadata.jsonList
Syntax
./nnl-mgmt.sh auth_metadata list [-pf (uaf|u2f|fido2)]Parameter | Description |
|---|---|
pf | Optional. Protocol family. One of
|
Description
Lists the authenticators.
Example
./nnl-mgmt.sh auth_metadata listSyntax
./nnl-mgmt.sh auth_metadata print (-aaid <aaid>|-aaguid <aaguid>|-acki <acki>)Parameter | Description |
|---|---|
aaid OR aaguid OR acki | Mandatory. Authenticator Metadata ID to be listed. One of
|
Description
Prints authenticator metadata.
Example
./nnl-mgmt.sh auth_metadata print -aaid ABCD#ABCDDelete
Syntax
./nnl-mgmt.sh auth_metadata delete (-aaid <aaid>|-aaguid <aaguid>|-acki <acki>) [-version <version>]Parameter | Description |
|---|---|
aaid OR aaguid OR acki | Mandatory. Authenticator Metadata ID to be deleted. One of
|
version | Optional. Version of the authenticator to be deleted. If the authenticator version is not provided, the command deletes authenticators matching the AAID regardless of version. |
Description
Deletes authenticator metadata.
Example
./nnl-mgmt.sh auth_metadata delete -aaid ABCD#ABCD -version 1