List
Syntax
./nnl-mgmt.sh policy list [-name <policy-name> -tenantid <tenantid>]Parameter | Description |
|---|---|
tenantid | Optional. Policies are listed for this tenant ID. Default value is default. |
name | Optional. Name of the policy to be listed. By default, the system lists all available policies for the designated tenant. |
Description
Lists FIDO policies for the given tenant. You can also see whether the policy is in Active or Draft status.
Example
./nnl-mgmt.sh policy list -name "device health policy" -tenantid defaultImport
Syntax
./nnl-mgmt.sh policy import -file <policy-file> [-overwrite <yes|no> ‑include‑metadata <yes|no> -tenantid <tenantid>]Parameter | Description |
|---|---|
file | Mandatory. Name of the policy file to import. A policy file can contain multiple FIDO policies. If you don’t provide a file name, the command fails. |
tenantid | Optional. The system imports policies into this tenant. Default value is default. |
overwrite | Specifies whether or not the system overwrites an existing FIDO policy or authenticator group that has the same name. The value is one of the following:
|
include-metadata | Optional. Specifies whether or not the system imports authenticator metadata. Applies when the ZIP file contains policies and authenticator metadata.
|
Description
This command imports FIDO policies from the specified import file into the designated tenant. All imported policies have a draft status. The import file can either be a JSON or ZIP file. A JSON file contains only policies. A ZIP file contains FIDO policies, the authenticator groups contained in the policy, and, optionally, authenticator metadata used by the authenticators in the authenticator groups.
If overwrite is yes, then existing FIDO policies and authenticator groups with the same name are overwritten. Overwrite handles objects differently depending on their type and status, as shown in the table below.
Object | Status of Existing Object | Result |
|---|---|---|
FIDO Policy | draft | The system overwrites the existing FIDO policy with the one from the file. Its status is draft. |
active | The system creates a draft FIDO policy with the same name. | |
Authenticator Groups | N/A | The system overwrites the existing authenticator group with the one from the file. This is true even if the authenticator group is being used by a different active FIDO Policy. |
You can optionally set include-metadata to yes in order to import authenticator metadata. Use this option in limited situations, such as you intend to use authenticator metadata that was only in a development deployment in a production deployment. Remember, authenticator metadata is accessible to all tenants in an S3 Suite installation and overwriting metadata could have unintended consequences.
This command fails to execute in the following scenarios:
If a draft policy exists and you specify no for overwrite.
If the file you are importing is larger than the maximum size of 128 KB. This default size can be changed by setting the nnl.policies.file.size.kb property for the Admin tenant.
Change the maximum size allowed for a FIDO policy file to 256 KB:
./nnl-mgmt.sh properties set -name nnl.policies.file.size.kb -value 256 ‑tenantid AdminExamples
Import FIDO policies from a JSON file
./nnl-mgmt.sh policy import -file device-health-policy.json -overwrite yes ‑tenantid financeImport a FIDO policy and its authenticator groups from a ZIP file
./nnl-mgmt.sh policy import -file device-health-policy.zip -overwrite yes ‑tenantid financeOr
./nnl-mgmt.sh policy import -file device-health-policy.zip -overwrite yes ‑include‑metadata no ‑tenantid financeImport a FIDO policy, its authenticator groups, and the authenticator metadata that it uses from a ZIP file
./nnl-mgmt.sh policy import -file device-health-policy.zip -overwrite yes ‑include‑metadata yes ‑tenantid financeExport
Syntax
./nnl-mgmt.sh policy export -name <policy-name> [-dir <policy-dir> | -file <file-path>] [-with-dependencies <yes|no> -include-metadata <yes|no> -tenantid <tenantid>]Parameter | Description |
|---|---|
name | Mandatory. Name of an active FIDO policy to export. If you don’t provide a name, the command fails. |
dir | Optional. Name of the destination directory where the system writes the export file. By default, the file is exported to the current directory. |
file | Optional. A file path. The system exports the FIDO policy and, if specified, the policy's dependencies and its associated authenticator metadata to the file path. The file cannot exist. |
tenantid | Optional. Policies defined in this tenant ID are exported. Default value is default. |
with-dependencies | Optional. Indicates if the system should export the authenticator groups referenced by the FIDO policy.
|
include-metadata | Optional. Only allowed if with-dependencies is yes. Indicates if the system should export authenticator metadata referenced in the FIDO policy.
|
Description
Exports the specified active FIDO policy defined in the given tenant. If only a policy is exported, the system creates a JSON file. If the policy’s authenticator groups and/or authenticator metadata are included, the system creates a ZIP file.
You either specify a directory or file path where the system exports the objects but not both. The file path already includes the directory. If you only specify dir, then the system generates the file name.
Examples
Export only a FIDO policy from the finance tenant (results in a JSON file)
./nnl-mgmt.sh policy export -name test1 -dir test_directory -tenantid financeExport a FIDO policy along with its authenticator groups (results in a ZIP file)
./nnl-mgmt.sh policy export -name test1 -dir test_directory -with-dependencies yes -tenantid marketingOr
./nnl-mgmt.sh policy export -name test1 -dir test_directory -with-dependencies yes -include-metadata no -tenantid marketingExport a FIDO policy, its authenticator groups, and the authenticator metadata that it uses (results in a ZIP file)
./nnl-mgmt.sh policy export -name test1 -dir test_directory -with-dependencies yes -include-metadata yes -tenantid marketingActivate
Syntax
./nnl-mgmt.sh policy activate -name <policy-name> [-tenantid <tenantid>]Parameter | Description |
|---|---|
name | Mandatory. The name of the policy file to activate. If you don’t provide a file name, the command fails. |
tenantid | Optional. Activates the policy specific to this tenant ID. Default value is default. |
Description
Activates a FIDO policy for the given tenant. A policy must be activated in order to be used.
Example
./nnl-mgmt.sh policy activate -name device-health-policy -tenantid tenantDelete
Syntax
./nnl-mgmt.sh policy delete -name <policy-name> -status <status> [-tenantid <tenantid>]Parameter | Description |
|---|---|
name | Mandatory. Name of the policy to delete. If you don’t provide a name, the command fails. |
status | Mandatory. Status of the policy file to delete. Status can be draft or active. |
tenantid | Optional. The system deletes the policy specific to this tenant ID. Default value is default. |
Description
Deletes a policy for the given tenant.
Example
./nnl-mgmt.sh policy delete -name DevicesForUser -tenantid finance -status active
./nnl-mgmt.sh policy delete -name DevicesForUser -tenantid finance -status draft