Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Appendix B: Run the Nok Nok Command Line Interface

Prev Next

Use the Nok Nok Command Line Interface (CLI) to configure your Nok Nok S3 Suite. The CDT package includes the run_cli.sh script that runs the nnl-mgmt.sh command-line utility from the CDT Host System.

Note that you cannot use the CLI to create complex objects like Adaptive Rulesets, Adaptive Rules, FIDO policies, or policy risk rules. These must be created and edited using the Server Admin Console, refer to 5.1. Login to the Nok Nok Admin Console section. . For more information about the available CLI commands, see Command line interface.

The Kubernetes pod that runs nnl-mgmt.sh commands, the CLI pod, is not deployed by default. You need to start it explicitly before you run the nnl-mgmt.sh commands. You may keep the CLI pod running or terminate it when you are finished running nnl-mgmt.sh commands. First start up the CLI pod from the CDT Host System terminal:

cd ${NN_CDT_HOME}
helm/bin/start_cli.sh

This deploys the CLI pod. Now you can use the run_cli.sh script to run the nnl-mgmt.sh from the CDT Host System terminal:

helm/bin/run_cli.sh -- nnl-mgmt.sh <command> <parameters>

Refer to Command line interface for information on available nnl-mgmt.sh commands and their parameters.

Here is an example that shows how to list the default tenant’s properties:

helm/bin/run_cli.sh -- nnl-mgmt.sh properties list

To take down the CLI pod, run this command.

helm/bin/stop_cli.sh

Export and Import Nok Nok Artifacts

Some of the nnl-mgmt.sh commands export or import Nok Nok properties, FIDO policies and other such artifacts. These commands read from or write to the /opt/mfas/shared folder in the CLI pod. Any path specified in the nnl-mgmt.sh command parameters must be relative to this folder.

Use the kubectl cp command to upload or download the files to or from the /opt/mfas/shared folder in the CLI pod. The following example shows how to export the default tenant’s properties and copy them to the CDT Host System. Run all of the following commands from the CDT Host System terminal:

1. Set the environment variable for the Kubernetes namespace used for the CDT deployment, and set the environment variable used for the CLI pod.

NS=$(grep NAMESPACE "${HOME}/.nn/cdt/deployment.profile" | sed -e 's/^NAMESPACE=//')
CLI_POD=$(kubectl get pod -n ${NS} -l app="nns3-cli" \
-o wide --no-headers=true 2>/dev/null | awk '{print $1;}')

2. Export the default tenant properties.

helm/bin/run_cli.sh -- nnl-mgmt.sh properties export -tenantid default

Expected output:

Successfully exported properties for tenant[default]
to [nnl-default-1686779977349.properties].

3. Copy the file to the CDT Host System.

kubectl cp ${NS}/${CLI_POD}:opt/mfas/shared/nnl-default-1686779977349.properties \
default_tenant.properties

The file is copied to the current working directory. If required, edit the default_tenant.properties file.

4. Copy the edited file back to the CLI container.

kubectl cp default_tenant.properties ${NS}/${CLI_POD}:opt/mfas/shared

5. Import the tenant properties.

helm/bin/run_cli.sh nnl-mgmt.sh properties import -file \ default_tenant.properties -tenantid default

This example shows how to download from the CLI pod:

kubectl cp ${NS}/${CLI_POD}:${NN_INSTALL_DIR}/shared/policy.json policy.json

This example shows how to upload a file from the host to the CLI pod:

kubectl cp policy.json ${NS}/${CLI_POD}:${NN_INSTALL_DIR}/shared/