tklmKeyUpdate
Use the tklmKeyUpdate command to update key metadata in the database. For example, you might move an individual key in one key group to another key group.
Purpose
Use this command to update key metadata in the database. For example, you might move an individual key in one key group to another key group.Permissions
您的角色必須具有修改動作的許可權,以及具有適當裝置群組的許可權。
Syntax
tklmKeyUpdate -uuid universalKeyID -usage {LTO | 3592 | DS5000 | DS8000 | GPFS | PEER_TO_PEER | DS8000_TCT | BRCD_ENCRYPTOR | ONESECURE | ETERNUS_DX | XIV | GENERIC | userdevicegroup} -attributes {attributevaluepair}{attributevaluepair}
Parameters
- -attributes
- Specify one or more of these attribute-value pairs:
- 已受損
- 指定金鑰的使用是否已受損。 唯一的值是 y(已受損)。 您無法將已受損金鑰或憑證變更為未受損狀態。
- groupName
- Specifies the name of a valid key group. You cannot move the last
key in a default key group to a different group.
However, you can change the key group name to a key group used by a different device group in the same device family, if the key group and any of its keys are not the device group default, or attached to a device. For example, you can change such a group from the myLTO device group to yourLTO device group in the LTO 裝置系列.
In the DS5000 裝置系列, a key group is generated for each DS5000 device when the device is created. You cannot create a DS5000 device with a key group attribute. However, you can create a new key group and specify the group name of a DS5000 device with the new key group.
- 資訊 informationstring
- 指定使用物件的相關資訊。
- -uuid
- Required. Specify the Universal Unique Identifier of the individual key that you want to move.
- -usage
- Specify a unique device group, such as LTO.
You can include the following values:
- LTO
- Specifies the LTO device group.
- 3592
- Specifies the 3592 device group.
- DS5000
- Specifies the DS5000 device group.
- DS8000
- Specifies the DS8000 device group.
- GPFS
- Specifies the IBM Spectrum Scale (previously known as GPFS) device group.
- PEER_TO_PEER
- Specifies the PEER_TO_PEER device group.
- DS8000_TCT
- Specifies the DS8000_TCT device group that is in the GPFS device family.
- BRCD_ENCRYPTOR
- 指定 LTO 裝置系列中的 BRCD_ENCRYPTOR 裝置群組。
- ONESECURE
- 指定 DS5000 裝置系列中的 ONESECURE 裝置群組。
- ETERNUS_DX
- 指定 DS5000 裝置系列中的 ETERNUS_DX 裝置群組。
- XIV
- 指定 IBM Spectrum Accelerate(之前稱為 XIV)裝置群組。
- GENERIC
- 指定使用金鑰管理交互作業能力通訊協定來與 IBM Security Key Lifecycle Manager 互動的裝置系列。
GENERIC 裝置群組能夠管理KMIP物件。
請勿使用指令行介面來將裝置新增至 GENERIC 裝置群組或變更 GENERIC 裝置群組屬性。
- userdevicegroup
- 指定基於受支援裝置系列的使用者定義群組。
Example
This Jython-formatted command updates the metadata for a key to indicate that the status of the key is compromised and describes the date of compromise.
print AdminTask.tklmKeyUpdate ('[-uuid KEY-a3ce9230-bef9-42bd-86b7-6d208ec119cf
-usage LTO -attributes "{compromised y} {information compromised_052208}"]')