Create
Syntax
./nnl-mgmt.sh tenant create -tenantid <tenantid> [-properties <property_file> -policy <policy_file> -ruleset <ruleset_file>]Parameter | Description |
|---|---|
tenantid | Mandatory. An alphanumeric string. Create a tenant by this name. If you don’t provide a value, the command fails. |
properties | Optional. The path to the property file that you want to import. Overwrites the default properties. If import fails, an exception is thrown but the remaining parameters for this command are executed. |
policy | Optional. The path to the policy file that you want to import. If import fails, an exception is thrown but the remaining parameters are executed. |
ruleset | Optional. The path to a ruleset file that you want to import. If import fails, an exception is thrown but the remaining parameters are executed. |
Description
This command always does the following regardless of the optional parameters:
Creates a new tenant
Generates and activates an encryption key for this tenant
Assigns default values to tenant properties. See Tenant Properties for the list of those properties and values.
You cannot create SYSTEM, Admin, or default tenants because these are built-in tenants. The tenantid is case-sensitive, and can contain only letters and digits. If you set a value for the nnl.restrict.input.field.regex property, then the server does not allow you to create a tenantid that conforms to that regex value. The server installation property nnl.restrict.input.field.regex is specified in the property NNL_JAVA_OPTS_PROPERTIES in the file nnl-install.properties. For more details refer to NNL_JAVA_OPTS_PROPERTIES's entry in Assign Server-related Properties.
Examples
To create a new finance tenant, use the example below.
./nnl-mgmt.sh tenant create -tenantid financeThis example shows how to create a new marketing tenant as well as import a policy, Adaptive Ruleset, and property values for it.
./nnl-mgmt.sh tenant create ‑tenantid marketing ‑policy device‑marketing‑policy.json ‑ruleset auth‑ruleset.json ‑properties nnl‑marketing.propertiesExport
Syntax
./nnl-mgmt.sh tenant export -tenantid <tenantid> -file <file_path> [-include-metadata <yes|no> -include-apiserver-config <yes|no>]Parameter | Description |
|---|---|
tenantid | Mandatory. Alphanumeric string. The tenant must exist and not be suspended. |
file | Mandatory. The path to the ZIP file where the Server stores the exported tenant configuration. |
include-apiserver-config | Optional. Indicates if the system should export the tenant's API Server's configuration objects.
|
include-metadata | Optional. Indicates if the system should export authenticator metadata referenced in the tenant's authenticator groups.
|
Description
Exports all of the configuration information for the tenant specified by tenantid. This command creates a ZIP file. The information exported may include:
Authentication Server Configuration
Configuration for the API Server and its plugins
Active Adaptive Rulesets
Active FIDO policies
Lists used by the active Adaptive Rulesets
authenticator groups
country lists
device model lists
geofence lists
IP address lists
WiFi network lists
An Admin user must have read access to the Configuration, Metadata Management, and Rulesets resources in the tenant to successfully export. To verify or modify an Admin user's permissions, see Assign Permissions to Admin Console Resources.
Below is an example showing the structure of the ZIP file that is exported.
$ tree default_All_Configurations_1694737766416
default_All_Configurations_1694737766416
├── api_server_config
│ ├── ExternalAuthenticationPlugin
│ │ ├── jwt_config.json
│ │ └── Main.json
│ ├── Main
│ │ ├── jwt_config.json
│ │ └── Main.json
│ ├── PolicyPlugin
│ │ ├── default_config.json
│ │ └── Main.json
│ ├── SessionPlugin
│ │ ├── credsim_config.json
│ │ ├── ip_address_plugin.json
│ │ ├── jws_config.json
│ │ ├── jwt_config.json
│ │ ├── Main.json
│ │ └── ua_parser.json
│ └── TransactionPlugin
│ ├── Main.json
│ └── jwt_config.json
├── lists
│ ├── L_authenticator_group_Android47iOSAnyBiometric-Hardware_1694737766387.json
│ └── ...
├── policies
│ ├── A_2nd_factor_ACTIVE_1694737766409.json
│ └── ...
├── properties
│ └── nnl-default-1694737766386.properties
├── rulesets
│ ├── A_default_ACTIVE_1700157172979.json
│ └── ...
└── manifest.infoExamples
To export the finance tenant with its API Server configuration and authenticator metadata, use the example below.
./nnl-mgmt.sh tenant export -tenantid finance -file /home/tom/EuropeTenant.zip ‑include‑apiserver‑config yes ‑include‑metadata yesThe command below exports the finance tenant without its API Server configuration or authenticator metadata. There is no need to provide the include-apiserver-config and include-metadata parameters because no is their default value.
./nnl-mgmt.sh tenant export -tenantid finance -file /home/tom/EuropeTenant.zipImport
Syntax
./nnl-mgmt.sh tenant import -tenantid <tenantid> -file <file_path> [-include-metadata <yes|no> -include-apiserver-config <yes|no>]Parameter | Description |
|---|---|
tenantid | Mandatory. Alphanumeric string. The tenant must exist and cannot be suspended. |
file | Mandatory. The path to a zip file containing tenant configuration information that was created by the tenant export command. |
include-apiserver-config | Optional. Indicates if the system should import the API Server's configuration objects from the file.
|
include-metadata | Optional. Indicates if the system should import authenticator metadata contained in the file.
|
Description
Imports configuration information from file into the tenant specified by tenantid. The file can contain the Authentication Server configuration, API Server configuration objects, apps, lists, FIDO policies, Adaptive Rulesets, and authenticator metadata. You can optionally specify if the tenant's existing API Server configuration and metadata used by its authenticator groups should be overridden by the content of the import file.
You cannot import configuration information for the SYSTEM tenant.
An Admin user must have write access to the Configuration, Metadata Management, and Rulesets resources in the tenant to successfully import. To verify or modify an Admin user's permissions, see Assign Permissions to Admin Console Resources.
Examples
To import the finance tenant from a zip file which includes its API Server configuration and authenticator metadata, use the example below.
./nnl-mgmt.sh tenant import -tenantid finance -file /home/tom/EuropeTenant.zip ‑include‑apiserver‑config yes ‑include‑metadata yesIf the zip file doesn’t contain authenticator metadata then don't provide the -include-metadata parameter.
./nnl-mgmt.sh tenant import -tenantid finance -file /home/tom/EuropeTenant.zip ‑include‑apiserver‑config yesDelete
Syntax
./nnl-mgmt.sh tenant delete -tenantid <tenantid>Parameter | Description |
|---|---|
tenantid | Mandatory. Tenant to delete. If you don’t provide a value, the command fails. |
Description
Deletes the specified tenant.
You cannot delete tenants named SYSTEM, Admin, or default since these are built-in tenants.
Example
./nnl-mgmt.sh tenant delete -tenantid financeList
Syntax
./nnl-mgmt.sh tenant list [-tenantid <tenantid>]Parameter | Description |
|---|---|
tenantid | Optional. The tenant’s ID. By default, the command lists all the tenants. |
Description
Lists the tenants in the system along with their status, either active or suspended.
Example
./nnl-mgmt.sh tenant list
+===========+===========+
| Tenant ID | Status |
+===========+===========+
| Admin | active |
| default | active |
| finance1 | active |
| finance | suspended |
+===========+===========+
./nnl-mgmt.sh tenant list -tenantid finance
+===========+===========+
| Tenant ID | Status |
+===========+===========+
| finance | suspended |
+===========+===========+Resume
Syntax
./nnl-mgmt.sh tenant resume -tenantid <tenantid>Parameter | Description |
|---|---|
tenantid | Mandatory. Resume all operations for the specified tenant. |
Description
Resumes a suspended tenant.
Example
./nnl-mgmt.sh tenant resume -tenantid financeSuspend
Syntax
./nnl-mgmt.sh tenant suspend -tenantid <tenantid>Parameter | Description |
|---|---|
tenantid | Mandatory. Tenant to suspend. |
Description
Suspends a tenant. Users in a suspended tenant cannot use their apps and administrative users cannot view or edit the tenant's FIDO policies, Adaptive Rulesets, or other configuration.
You cannot suspend tenants named SYSTEM or Admin since these are special built-in tenants.
Example
./nnl-mgmt.sh tenant suspend -tenantid finance