Use these commands to manage various lists used by FIDO policies and Adaptive Rulesets. These lists include:
Authenticator groups
Countries
Geofences
Device models
IP addresses
WiFi networks
The expected usage model is that you export lists from existing tenants and import them into new tenants.
Import
Syntax
./nnl-mgmt.sh list import -type (countries | geo_fences | ip_address | wifi_networks | device_models | authenticator_group) -file <list-file> [-tenantid <tenantid> -overwrite <yes|no>]Parameter | Description |
|---|---|
type | Mandatory. List type. One of:
|
file | Mandatory. Name of the JSON file containing the list to import. |
tenantid | Optional. Imports the list for this tenant ID. Default value is default. |
overwrite | Optional. The value can be one of the following:
|
Description
Imports a file containing a list for the specified list type and tenant. The command assumes there is only one type of list contained in the file.
By default, the file size of any list file must be less than 128 KB. Change the maximum file size for a list file by setting its associated file size property in the Admin tenant using the Command Line Interface nnl-mgmt.sh.
File Size Property | Associated List Type |
|---|---|
nnl.list.auth.group.file.size.kb | authenticator group list |
nnl.list.country.file.size.kb | country list |
nnl.list.device.model.file.size.kb | device model list |
nnl.list.geofence.file.size.kb | geofence list |
nnl.list.ip.address.file.size.kb | ip-address list |
nnl.list.wifi.address.file.size.kb | wifi networks address list |
Examples
./nnl-mgmt.sh list import -type countries -file countries_list.json -tenantid finance -overwrite noIncrease maximum file size limit for a wifi address list file to 256 KB.
./nnl-mgmt.sh properties set -name nnl.list.wifi.address.file.size.kb -value 256 ‑tenantid AdminExport
Syntax
./nnl-mgmt.sh list export -type (countries | geo_fences | ip_address | wifi_networks | device_models | authenticator_group) [-name <list-name>] [-dir <dir-path> | -file <file-path>] [-tenantid <tenantid>]Parameter | Description |
|---|---|
type | Mandatory. List type. One of:
|
name | Optional. Case-sensitive, alphanumeric string. Name of the list to export. By default, all the lists of the specified type are exported. |
dir | Optional. Name of the destination directory to store the exported list. By default, the command exports the list to the current directory. |
file | Optional. The file path where the system exports the list. The file cannot exist. |
tenantid | Optional. Export the list from this tenant ID. Default value is default. |
Description
Exports a list of the specified type from the given tenant as a JSON file.
You either specify a directory or file path where the system exports the data lists, not both. The file path already includes the directory. If you only specify dir, then the system generates the file name.
Example
The command below exports the authenticator group called Biometric Authenticators and writes the information out to /testdir. The system generates the file name.
./nnl-mgmt.sh list export -type authenticator_group -name "Biometric Authenticators" -dir /testdir -tenantid financeThe command below exports the restricted countries list and writes the information to /home/lists/restricted.json.
./nnl-mgmt.sh list export -type countries -name restricted -file /home/lists/restricted.json -tenantid globalList
Syntax
./nnl-mgmt.sh list list -type (countries | geo_fences | ip_address | wifi_networks | device_models | authenticator_group) [-name <list-name> -tenantid <tenantid>]Parameter | Description |
|---|---|
type | Mandatory. List type. One of:
|
name | Optional. Display lists with this name. By default, the system lists all lists of the specified type for the tenant. |
tenantid | Optional. Display lists associated with this tenant ID. Default value is default. |
Description
Lists the names and descriptions for the lists defined in the specified tenant.
Example
./nnl-mgmt.sh list list -type device_models -name test-devices-list -tenantid financeDelete
Syntax
./nnl-mgmt.sh list delete -type (countries | geo_fences | ip_address | wifi_networks | device_models | authenticator_group) -name <list-name> [-tenantid <tenantid>]Parameter | Description |
|---|---|
name | Mandatory. Delete the list with this name. If you don’t provide a value, the command fails. |
type | Mandatory. List type. One of:
|
tenantid | Optional. Delete the list defined for this tenant ID. Default value is default. |
Description
Delete a list specific to this tenant ID.
Example
./nnl-mgmt.sh list delete -type ip_address -name ip-address-allow-list -tenantid finance