Use these commands to manage your tenants’ encryption keys. There can be only one active encryption key per tenant.
Add
Syntax
./nnl-mgmt.sh key add [-tenantid <tenantid> -autogenerate <yes|no>]Parameter | Description |
|---|---|
tenantid | Optional. Tenant ID. Default value is default. |
autogenerate | Optional. Value can be one of:
The value defaults to yes. |
Description
Creates a new active encryption key for a tenant and returns the key’s keyhandle. If you don’t provide a tenant ID, a new encryption key is added to the default tenant. You can force encryption key replacement by assigning yes to autogenerate.
Examples
./nnl-mgmt.sh key add -tenantid acme -autogenerate yesSample result:
Encryption key added successfully. Keyhandle is 7The following example applies if you implement the Crypto plugin.
./nnl-mgmt.sh key add -tenantid default -autogenerate noSample result with both Secrets and Crypto plugins installed:
Please enter the alias to the encryption key :
defaultalias
Encryption key added sucessfully. Keyhandle is 1Delete
Syntax
./nnl-mgmt.sh key delete -keyhandle <keyhandle> [-tenantid <tenantid>]Parameter | Description |
|---|---|
tenantid | Optional. Tenant ID. Default value is default. |
keyhandle | Mandatory. The keyhandle identifies a specific key and is an integer. |
Description
Delete compromised keys with this command. Only OBSOLETE keys can be deleted. Once a key is deleted, it cannot be reused.
Example
./nnl-mgmt.sh key delete -keyhandle 5List
Syntax
./nnl-mgmt.sh key list [-tenantid <tenantid> -keyhandle <keyhandle>]Parameter | Description |
|---|---|
tenantid | Optional. Tenant ID. Default value is default. |
keyhandle | Optional. The keyhandle uniquely identifies a key and is an integer. |
Description
Lists the tenant ID, keyhandle, and status for the key identified by keyhandle for the specified tenant. If you don’t specify keyhandle, then information is listed for all of the tenant’s keys. If you don’t specify a tenant, the command lists information for the default tenant’s keys.
Example
./nnl-mgmt.sh key list -tenantid acmeSetactive
Syntax
./nnl-mgmt.sh key setactive -keyhandle <keyhandle> [-tenantid <tenantid>]Parameter | Description |
|---|---|
tenantid | Optional. Tenant ID. Default value is default. |
keyhandle | Mandatory. The keyhandle uniquely identifies a key and is an integer. |
Description
Changes the status of the current active key to OBSOLETE. Changes the status of the key associated with keyhandle to ACTIVE. Only one key can be active per tenant at a time. You can reactivate an OBSOLETE key.
If you don’t specify a tenant ID, the system applies this command to the default tenant.
Example
./nnl-mgmt.sh key setactive -keyhandle 2 -tenantid acme