Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Encryption Key Commands

Prev Next

Use these commands to manage your tenants’ encryption keys. There can be only one active encryption key per tenant.

Add

Syntax

./nnl-mgmt.sh key add [-tenantid <tenantid> -autogenerate <yes|no>]

Parameter

Description

tenantid

Optional. Tenant ID. Default value is default.

autogenerate

Optional. Value can be one of:

  • yes: Generates a new active key for the tenant, regardless of whether the tenant already has a key.

  • no: Only generates a new key if the tenant doesn’t have a key. Use this option if you implement the Crypto plugin.

The value defaults to yes.

Description

Creates a new active encryption key for a tenant and returns the key’s keyhandle. If you don’t provide a tenant ID, a new encryption key is added to the default tenant. You can force encryption key replacement by assigning yes to autogenerate.

Examples

./nnl-mgmt.sh key add -tenantid acme -autogenerate yes

Sample result:

Encryption key added successfully. Keyhandle is 7

The following example applies if you implement the Crypto plugin.

./nnl-mgmt.sh key add -tenantid default -autogenerate no

Sample result with both Secrets and Crypto plugins installed:

Please enter the alias to the encryption key :
defaultalias
Encryption key added sucessfully. Keyhandle is 1

Delete

Syntax

./nnl-mgmt.sh key delete -keyhandle <keyhandle> [-tenantid <tenantid>]

Parameter

Description

tenantid

Optional. Tenant ID. Default value is default.

keyhandle

Mandatory. The keyhandle identifies a specific key and is an integer.

Description

Delete compromised keys with this command. Only OBSOLETE keys can be deleted. Once a key is deleted, it cannot be reused.

Example

./nnl-mgmt.sh key delete -keyhandle 5

List

Syntax

./nnl-mgmt.sh key list [-tenantid <tenantid> -keyhandle <keyhandle>]

Parameter

Description

tenantid

Optional. Tenant ID. Default value is default.

keyhandle

Optional. The keyhandle uniquely identifies a key and is an integer.

Description

Lists the tenant ID, keyhandle, and status for the key identified by keyhandle for the specified tenant. If you don’t specify keyhandle, then information is listed for all of the tenant’s keys. If you don’t specify a tenant, the command lists information for the default tenant’s keys.

Example

./nnl-mgmt.sh key list -tenantid acme

Setactive

Syntax

./nnl-mgmt.sh key setactive -keyhandle <keyhandle> [-tenantid <tenantid>]

Parameter

Description

tenantid

Optional. Tenant ID. Default value is default.

keyhandle

Mandatory. The keyhandle uniquely identifies a key and is an integer.

Description

Changes the status of the current active key to OBSOLETE. Changes the status of the key associated with keyhandle to ACTIVE. Only one key can be active per tenant at a time. You can reactivate an OBSOLETE key.

If you don’t specify a tenant ID, the system applies this command to the default tenant.

Example

./nnl-mgmt.sh key setactive -keyhandle 2 -tenantid acme