nethsm-openpgp-import(1) General Commands Manual nethsm-openpgp-import(1)

nethsm-openpgp-import - Import OpenPGP TSK-formatted private key

nethsm openpgp import [-k|--key-id] [-t|--tags] [-a|--auth-passphrase-file] [-c|--config] [-l|--label] [-u|--user] [-h|--help] <TSK_FILE>

Import OpenPGP Transferable Secret Key (TSK) formatted private key

Only TSKs with a single component key are supported.

System-wide users in the "Administrator" role can only import TSKs as system-wide keys. Namespaced users in the "Administrator" role can only import TSKs as keys in their own namespace.

Note: Although assigning tags to the new key is optional, it is highly recommended as not doing so means that all users in the same scope have access to it!

Requires authentication of a user in the "Administrator" role.

An optional unique ID that is assigned to the imported key

If none is provided a generic one is generated for the key.

May also be specified with the NETHSM_OPENPGP_KEY_ID environment variable.
An optional list of tags that are assigned to the imported key

Tags on keys are used to grant access to those keys for users that carry the same tags.

May also be specified with the NETHSM_OPENPGP_KEY_TAGS environment variable.
The path to a file containing a passphrase for authentication

The passphrase provided in the file must be the one for the user chosen for the command.

This option can be provided multiple times, which is needed for commands that require multiple roles at once. With multiple passphrase files ordering matters, as the files are assigned to the respective user provided by the "--user" option.

May also be specified with the NETHSM_AUTH_PASSPHRASE_FILE environment variable.
The path to a custom configuration file

If specified, the custom configuration file is used instead of the default configuration file location.

May also be specified with the NETHSM_CONFIG environment variable.
A label uniquely identifying a device in the configuration file

Must be provided if more than one device is setup in the configuration file.

May also be specified with the NETHSM_LABEL environment variable.
A user name which is used for a command

Can be provided, if no user name is setup in the configuration file for a device. Must be provided, if several user names of the same target role are setup in the configuration file for a device.

This option can be provided multiple times, which is needed for commands that require multiple roles at once.

May also be specified with the NETHSM_USER environment variable.
Print help (see a summary with '-h')
<TSK_FILE>
The path to the Transferable Secret Key file to import
May also be specified with the NETHSM_OPENPGP_TSK_FILE environment variable.
nethsm-openpgp-import