Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Tenant Commands

Prev Next

Create

Syntax

./nnl-mgmt.sh tenant create -tenantid <tenantid> [-properties <property_file> -policy <policy_file> -ruleset <ruleset_file>]

Parameter

Description

tenantid

Mandatory. An alphanumeric string. Create a tenant by this name. If you don’t provide a value, the command fails.

properties

Optional. The path to the property file that you want to import. Overwrites the default properties. If import fails, an exception is thrown but the remaining parameters for this command are executed.

policy

Optional. The path to the policy file that you want to import. If import fails, an exception is thrown but the remaining parameters are executed.

ruleset

Optional. The path to a ruleset file that you want to import. If import fails, an exception is thrown but the remaining parameters are executed.

Description

This command always does the following regardless of the optional parameters:

  • Creates a new tenant

  • Generates and activates an encryption key for this tenant

  • Assigns default values to tenant properties. See Tenant Properties for the list of those properties and values.

You cannot create SYSTEM, Admin, or default tenants because these are built-in tenants. The tenantid is case-sensitive, and can contain only letters and digits. If you set a value for the nnl.restrict.input.field.regex property, then the server does not allow you to create a tenantid that conforms to that regex value. The server installation property nnl.restrict.input.field.regex is specified in the property NNL_JAVA_OPTS_PROPERTIES in the file nnl-install.properties. For more details refer to NNL_JAVA_OPTS_PROPERTIES's entry in Assign Server-related Properties.

Examples

To create a new finance tenant, use the example below.

./nnl-mgmt.sh tenant create -tenantid finance

This example shows how to create a new marketing tenant as well as import a policy, Adaptive Ruleset, and property values for it.

./nnl-mgmt.sh tenant create ‑tenantid marketing ‑policy device‑marketing‑policy.json ‑ruleset auth‑ruleset.json ‑properties nnl‑marketing.properties

Export

Syntax

./nnl-mgmt.sh tenant export -tenantid <tenantid> -file <file_path> [-include-metadata <yes|no> -include-apiserver-config <yes|no>]

Parameter

Description

tenantid

Mandatory. Alphanumeric string. The tenant must exist and not be suspended.

file

Mandatory. The path to the ZIP file where the Server stores the exported tenant configuration.

include-apiserver-config

Optional. Indicates if the system should export the tenant's API Server's configuration objects.

  • Yes: The system exports the API Server's configuration objects.

  • No (default): The system does not export the API Server's configuration objects.

include-metadata

Optional. Indicates if the system should export authenticator metadata referenced in the tenant's authenticator groups.

  • Yes: The system exports authenticator metadata.

  • No (default): The system does not export authenticator metadata.

Description

Exports all of the configuration information for the tenant specified by tenantid. This command creates a ZIP file. The information exported may include:

  • Authentication Server Configuration

  • Configuration for the API Server and its plugins

  • Active Adaptive Rulesets

  • Active FIDO policies

  • Lists used by the active Adaptive Rulesets

    • authenticator groups

    • country lists

    • device model lists

    • geofence lists

    • IP address lists

    • WiFi network lists

An Admin user must have read access to the Configuration, Metadata Management, and Rulesets resources in the tenant to successfully export. To verify or modify an Admin user's permissions, see Assign Permissions to Admin Console Resources.

Below is an example showing the structure of the ZIP file that is exported.

$ tree default_All_Configurations_1694737766416
default_All_Configurations_1694737766416
├── api_server_config
│   ├── ExternalAuthenticationPlugin
│   │   ├── jwt_config.json
│   │   └── Main.json
│   ├── Main
│   │   ├── jwt_config.json
│   │   └── Main.json
│   ├── PolicyPlugin
│   │   ├── default_config.json
│   │   └── Main.json
│   ├── SessionPlugin
│   │   ├── credsim_config.json
│   │   ├── ip_address_plugin.json
│   │   ├── jws_config.json
│   │   ├── jwt_config.json
│   │   ├── Main.json
│   │   └── ua_parser.json
│   └── TransactionPlugin
│       ├── Main.json
│       └── jwt_config.json
├── lists
│   ├── L_authenticator_group_Android47iOSAnyBiometric-Hardware_1694737766387.json
│   └── ...
├── policies
│   ├── A_2nd_factor_ACTIVE_1694737766409.json
│   └── ...
├── properties
│   └── nnl-default-1694737766386.properties
├── rulesets
│   ├── A_default_ACTIVE_1700157172979.json
│   └── ...
└── manifest.info

Examples

To export the finance tenant with its API Server configuration and authenticator metadata, use the example below.

./nnl-mgmt.sh tenant export -tenantid finance -file /home/tom/EuropeTenant.zip ‑include‑apiserver‑config yes ‑include‑metadata yes

The command below exports the finance tenant without its API Server configuration or authenticator metadata. There is no need to provide the include-apiserver-config and include-metadata parameters because no is their default value.

./nnl-mgmt.sh tenant export -tenantid finance -file /home/tom/EuropeTenant.zip

Import

Syntax

./nnl-mgmt.sh tenant import -tenantid <tenantid> -file <file_path> [-include-metadata <yes|no> -include-apiserver-config <yes|no>]

Parameter

Description

tenantid

Mandatory. Alphanumeric string. The tenant must exist and cannot be suspended.

file

Mandatory. The path to a zip file containing tenant configuration information that was created by the tenant export command.

include-apiserver-config

Optional. Indicates if the system should import the API Server's configuration objects from the file.

  • Yes: The system imports the API Server's configuration objects.

  • No (default): The system does not import the API Server's configuration objects.

include-metadata

Optional. Indicates if the system should import authenticator metadata contained in the file.

  • Yes: The system imports authenticator metadata.

  • No (default): The system does not import authenticator metadata.

Description

Imports configuration information from file into the tenant specified by tenantid. The file can contain the Authentication Server configuration, API Server configuration objects, apps, lists, FIDO policies, Adaptive Rulesets, and authenticator metadata. You can optionally specify if the tenant's existing API Server configuration and metadata used by its authenticator groups should be overridden by the content of the import file.

You cannot import configuration information for the SYSTEM tenant.

An Admin user must have write access to the Configuration, Metadata Management, and Rulesets resources in the tenant to successfully import. To verify or modify an Admin user's permissions, see Assign Permissions to Admin Console Resources.

Examples

To import the finance tenant from a zip file which includes its API Server configuration and authenticator metadata, use the example below.

./nnl-mgmt.sh tenant import -tenantid finance -file /home/tom/EuropeTenant.zip ‑include‑apiserver‑config yes ‑include‑metadata yes

If the zip file doesn’t contain authenticator metadata then don't provide the -include-metadata parameter.

./nnl-mgmt.sh tenant import -tenantid finance -file /home/tom/EuropeTenant.zip ‑include‑apiserver‑config yes

Delete

Syntax

./nnl-mgmt.sh tenant delete -tenantid <tenantid>

Parameter

Description

tenantid

Mandatory. Tenant to delete. If you don’t provide a value, the command fails.

Description

Deletes the specified tenant.

You cannot delete tenants named SYSTEM, Admin, or default since these are built-in tenants.

Example

./nnl-mgmt.sh tenant delete -tenantid finance

List

Syntax

./nnl-mgmt.sh tenant list [-tenantid <tenantid>]

Parameter

Description

tenantid

Optional. The tenant’s ID. By default, the command lists all the tenants.

Description

Lists the tenants in the system along with their status, either active or suspended.

Example

./nnl-mgmt.sh tenant list
+===========+===========+
| Tenant ID | Status    |
+===========+===========+
| Admin     | active    |
| default   | active    |
| finance1  | active    |
| finance   | suspended |
+===========+===========+
./nnl-mgmt.sh tenant list -tenantid finance
+===========+===========+
| Tenant ID | Status    |
+===========+===========+
| finance   | suspended |
+===========+===========+

Resume

Syntax

./nnl-mgmt.sh tenant resume -tenantid <tenantid>

Parameter

Description

tenantid

Mandatory. Resume all operations for the specified tenant.

Description

Resumes a suspended tenant.

Example

./nnl-mgmt.sh tenant resume -tenantid finance

Suspend

Syntax

./nnl-mgmt.sh tenant suspend -tenantid <tenantid>

Parameter

Description

tenantid

Mandatory. Tenant to suspend.

Description

Suspends a tenant. Users in a suspended tenant cannot use their apps and administrative users cannot view or edit the tenant's FIDO policies, Adaptive Rulesets, or other configuration.

You cannot suspend tenants named SYSTEM or Admin since these are special built-in tenants.

Example

./nnl-mgmt.sh tenant suspend -tenantid finance