Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

FIDO Policy Commands

Prev Next

List

Syntax

./nnl-mgmt.sh policy list [-name <policy-name> -tenantid <tenantid>]

Parameter

Description

tenantid

Optional. Policies are listed for this tenant ID. Default value is default.

name

Optional. Name of the policy to be listed. By default, the system lists all available policies for the designated tenant.

Description

Lists FIDO policies for the given tenant. You can also see whether the policy is in Active or Draft status.

Example

./nnl-mgmt.sh policy list -name "device health policy" -tenantid default

Import

Syntax

./nnl-mgmt.sh policy import -file <policy-file> [-overwrite <yes|no> ‑include‑metadata <yes|no> -tenantid <tenantid>]

Parameter

Description

file

Mandatory. Name of the policy file to import. A policy file can contain multiple FIDO policies. If you don’t provide a file name, the command fails.

tenantid

Optional. The system imports policies into this tenant. Default value is default.

overwrite

Specifies whether or not the system overwrites an existing FIDO policy or authenticator group that has the same name. The value is one of the following:

  • Yes: The system overwrites objects with the same name.

  • No (default): The system does not overwrite an object with the same name.

include-metadata

Optional. Specifies whether or not the system imports authenticator metadata. Applies when the ZIP file contains policies and authenticator metadata.

  • Yes: The system imports and overwrites authenticator metadata.

  • No (default): The system doesn’t import authenticator metadata.

Description

This command imports FIDO policies from the specified import file into the designated tenant. All imported policies have a draft status. The import file can either be a JSON or ZIP file. A JSON file contains only policies. A ZIP file contains FIDO policies, the authenticator groups contained in the policy, and, optionally, authenticator metadata used by the authenticators in the authenticator groups.

If overwrite is yes, then existing FIDO policies and authenticator groups with the same name are overwritten. Overwrite handles objects differently depending on their type and status, as shown in the table below.

Object

Status of Existing Object

Result

FIDO Policy

draft

The system overwrites the existing FIDO policy with the one from the file. Its status is draft.

active

The system creates a draft FIDO policy with the same name.

Authenticator Groups

N/A

The system overwrites the existing authenticator group with the one from the file. This is true even if the authenticator group is being used by a different active FIDO Policy.

You can optionally set include-metadata to yes in order to import authenticator metadata. Use this option in limited situations, such as you intend to use authenticator metadata that was only in a development deployment in a production deployment. Remember, authenticator metadata is accessible to all tenants in an S3 Suite installation and overwriting metadata could have unintended consequences.

This command fails to execute in the following scenarios:

  • If a draft policy exists and you specify no for overwrite.

  • If the file you are importing is larger than the maximum size of 128 KB. This default size can be changed by setting the nnl.policies.file.size.kb property for the Admin tenant.

Change the maximum size allowed for a FIDO policy file to 256 KB:

./nnl-mgmt.sh properties set -name nnl.policies.file.size.kb -value 256 ‑tenantid Admin

Examples

Import FIDO policies from a JSON file

./nnl-mgmt.sh policy import -file device-health-policy.json -overwrite yes ‑tenantid finance

Import a FIDO policy and its authenticator groups from a ZIP file

./nnl-mgmt.sh policy import -file device-health-policy.zip -overwrite yes  ‑tenantid finance

Or

./nnl-mgmt.sh policy import -file device-health-policy.zip -overwrite yes ‑include‑metadata no ‑tenantid finance

Import a FIDO policy, its authenticator groups, and the authenticator metadata that it uses from a ZIP file

./nnl-mgmt.sh policy import -file device-health-policy.zip -overwrite yes ‑include‑metadata yes ‑tenantid finance

Export

Syntax

./nnl-mgmt.sh policy export -name <policy-name> [-dir <policy-dir> | -file <file-path>] [-with-dependencies <yes|no> -include-metadata <yes|no> -tenantid <tenantid>]

Parameter

Description

name

Mandatory. Name of an active FIDO policy to export. If you don’t provide a name, the command fails.

dir

Optional. Name of the destination directory where the system writes the export file. By default, the file is exported to the current directory.

file

Optional. A file path. The system exports the FIDO policy and, if specified, the policy's dependencies and its associated authenticator metadata to the file path. The file cannot exist.

tenantid

Optional. Policies defined in this tenant ID are exported. Default value is default.

with-dependencies

Optional. Indicates if the system should export the authenticator groups referenced by the FIDO policy.

  • Yes: The system exports authenticator groups .

  • No (default): The system does not export authenticator groups.

include-metadata

Optional. Only allowed if with-dependencies is yes. Indicates if the system should export authenticator metadata referenced in the FIDO policy.

  • Yes: The system exports authenticator metadata referenced by the FIDO policy.

  • No (default): The system does not export authenticator metadata.

Description

Exports the specified active FIDO policy defined in the given tenant. If only a policy is exported, the system creates a JSON file. If the policy’s authenticator groups and/or authenticator metadata are included, the system creates a ZIP file.

You either specify a directory or file path where the system exports the objects but not both. The file path already includes the directory. If you only specify dir, then the system generates the file name.

Examples

Export only a FIDO policy from the finance tenant (results in a JSON file)

./nnl-mgmt.sh policy export -name test1 -dir test_directory -tenantid finance

Export a FIDO policy along with its authenticator groups (results in a ZIP file)

./nnl-mgmt.sh policy export -name test1 -dir test_directory -with-dependencies yes -tenantid marketing

Or

./nnl-mgmt.sh policy export -name test1 -dir test_directory -with-dependencies yes -include-metadata no -tenantid marketing

Export a FIDO policy, its authenticator groups, and the authenticator metadata that it uses (results in a ZIP file)

./nnl-mgmt.sh policy export -name test1 -dir test_directory -with-dependencies yes -include-metadata yes -tenantid marketing

Activate

Syntax

./nnl-mgmt.sh policy activate -name <policy-name> [-tenantid <tenantid>]

Parameter

Description

name

Mandatory. The name of the policy file to activate. If you don’t provide a file name, the command fails.

tenantid

Optional. Activates the policy specific to this tenant ID. Default value is default.

Description

Activates a FIDO policy for the given tenant. A policy must be activated in order to be used.

Example

./nnl-mgmt.sh policy activate -name device-health-policy -tenantid tenant

Delete

Syntax

./nnl-mgmt.sh policy delete -name <policy-name> -status <status> [-tenantid <tenantid>]

Parameter

Description

name

Mandatory. Name of the policy to delete. If you don’t provide a name, the command fails.

status

Mandatory. Status of the policy file to delete. Status can be draft or active.

tenantid

Optional. The system deletes the policy specific to this tenant ID. Default value is default.

Description

Deletes a policy for the given tenant.

Example

./nnl-mgmt.sh policy delete -name DevicesForUser -tenantid finance -status active
./nnl-mgmt.sh policy delete -name DevicesForUser -tenantid finance -status draft