IBM Security Key Lifecycle Manager, Version 3.0.1

tklmKeyUpdate

Use the tklmKeyUpdate command to update key metadata in the database. For example, you might move an individual key in one key group to another key group.

Note: The IBM Security Key Lifecycle Manager command-line interface commands will be deprecated in the later versions of IBM Security Key Lifecycle Manager. Use the REST interfaces instead.

Purpose

Use this command to update key metadata in the database. For example, you might move an individual key in one key group to another key group.

Permissions

您的角色必須具有修改動作的許可權,以及具有適當裝置群組的許可權。

Syntax

tklmKeyUpdate -uuid universalKeyID -usage {LTO | 3592 | DS5000 | DS8000 | GPFS | PEER_TO_PEER | DS8000_TCT | BRCD_ENCRYPTOR | ONESECURE | ETERNUS_DX | XIV | GENERIC | userdevicegroup} -attributes {attributevaluepair}{attributevaluepair}

Parameters

-attributes
Specify one or more of these attribute-value pairs:
已受損
指定金鑰的使用是否已受損。 唯一的值是 y(已受損)。 您無法將已受損金鑰或憑證變更為未受損狀態。
groupName
Specifies the name of a valid key group. You cannot move the last key in a default key group to a different group.

However, you can change the key group name to a key group used by a different device group in the same device family, if the key group and any of its keys are not the device group default, or attached to a device. For example, you can change such a group from the myLTO device group to yourLTO device group in the LTO 裝置系列.

In the DS5000 裝置系列, a key group is generated for each DS5000 device when the device is created. You cannot create a DS5000 device with a key group attribute. However, you can create a new key group and specify the group name of a DS5000 device with the new key group.

資訊 informationstring
指定使用物件的相關資訊。
-uuid
Required. Specify the Universal Unique Identifier of the individual key that you want to move.
-usage
Specify a unique device group, such as LTO.

You can include the following values:

LTO
Specifies the LTO device group.
3592
Specifies the 3592 device group.
DS5000
Specifies the DS5000 device group.
DS8000
Specifies the DS8000 device group.
GPFS
Specifies the IBM Spectrum Scale (previously known as GPFS) device group.
PEER_TO_PEER
Specifies the PEER_TO_PEER device group.
DS8000_TCT
Specifies the DS8000_TCT device group that is in the GPFS device family.
BRCD_ENCRYPTOR
指定 LTO 裝置系列中的 BRCD_ENCRYPTOR 裝置群組
ONESECURE
指定 DS5000 裝置系列中的 ONESECURE 裝置群組
ETERNUS_DX
指定 DS5000 裝置系列中的 ETERNUS_DX 裝置群組。
XIV
指定 IBM Spectrum Accelerate(之前稱為 XIV)裝置群組。
GENERIC
指定使用金鑰管理交互作業能力通訊協定來與 IBM Security Key Lifecycle Manager 互動的裝置系列。 GENERIC 裝置群組能夠管理KMIP物件。

請勿使用指令行介面來將裝置新增至 GENERIC 裝置群組或變更 GENERIC 裝置群組屬性。

userdevicegroup
指定基於受支援裝置系列的使用者定義群組。

Example

This Jython-formatted command updates the metadata for a key to indicate that the status of the key is compromised and describes the date of compromise.

print AdminTask.tklmKeyUpdate ('[-uuid KEY-a3ce9230-bef9-42bd-86b7-6d208ec119cf 
	-usage LTO -attributes "{compromised y} {information compromised_052208}"]')


Feedback