nethsm-key(1) General Commands Manual nethsm-key(1)

nethsm-key - Operate on the keys of a device

nethsm key [-a|--auth-passphrase-file] [-c|--config] [-l|--label] [-u|--user] [-h|--help] <subcommands>

Operate on the keys of a device

Supports all relevant cryptographic operations (decrypt, encrypt, sign), certificate handling, importing, generation and ACL management.

Keys may exist in specific scopes: system-wide or in namespaces (see "nethsm namespace"). While system-wide users only have access to system-wide keys, namespaced users only have access to keys in their own namespace.

The path to a file containing a passphrase for authentication

The passphrase provided in the file must be the one for the user chosen for the command.

This option can be provided multiple times, which is needed for commands that require multiple roles at once. With multiple passphrase files ordering matters, as the files are assigned to the respective user provided by the "--user" option.

May also be specified with the NETHSM_AUTH_PASSPHRASE_FILE environment variable.
The path to a custom configuration file

If specified, the custom configuration file is used instead of the default configuration file location.

May also be specified with the NETHSM_CONFIG environment variable.
A label uniquely identifying a device in the configuration file

Must be provided if more than one device is setup in the configuration file.

May also be specified with the NETHSM_LABEL environment variable.
A user name which is used for a command

Can be provided, if no user name is setup in the configuration file for a device. Must be provided, if several user names of the same target role are setup in the configuration file for a device.

This option can be provided multiple times, which is needed for commands that require multiple roles at once.

May also be specified with the NETHSM_USER environment variable.
Print help (see a summary with '-h')

Operate on certificates for a key
Get a Certificate Signing Request for a key
Decrypt a message using a key
Encrypt a message using a key
Generate a new key
Get information on a key
Import a key
List all key IDs
Get the public key for a key
Remove a key
Sign a message using a key
Tag a key
Untag a key
Print this message or the help of the given subcommand(s)
nethsm-key