az iot adr ns ca policy
Note
This reference is part of the azure-iot extension for the Azure CLI (version 2.73.0 or higher). The extension will automatically install the first time you run an az iot adr ns ca policy command. Learn more about extensions.
Command group 'iot adr ns ca' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
Manage certificate policies for a certificate authority.
A certificate policy carries the leaf certificate issuance settings for a certificate authority.
Commands
| Name | Description | Type | Status |
|---|---|---|---|
| az iot adr ns ca policy create |
Create a certificate policy for a certificate authority. |
Extension | Preview |
| az iot adr ns ca policy delete |
Delete a certificate policy from a certificate authority. |
Extension | Preview |
| az iot adr ns ca policy list |
List the certificate policies for a certificate authority. |
Extension | Preview |
| az iot adr ns ca policy show |
Show a certificate policy for a certificate authority. |
Extension | Preview |
| az iot adr ns ca policy update |
Update a certificate policy for a certificate authority. |
Extension | Preview |
| az iot adr ns ca policy wait |
Wait for a certificate policy to reach a desired state. |
Extension | Preview |
az iot adr ns ca policy create
Command group 'iot adr ns ca policy' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
Create a certificate policy for a certificate authority.
Certificate policies can only be created under an issuing certificate authority with type ICA. Create the ICA under a Root CA, then pass the ICA name to --ca-name. The leaf certificate validity period must be between 1 and 90 days, inclusive. Use 'ca policy update --validity-days' to change the validity period of an existing policy.
az iot adr ns ca policy create --ca --ca-name
--name --pn --policy-name
--namespace --ns
--resource-group
--validity-days --vd
[--acquire-policy-token]
[--change-reference]
[--location]
[--no-wait]
[--tags]
Examples
Create a certificate policy with a 30 day leaf certificate validity period
az iot adr ns ca policy create -n myPolicy --ca-name myICA --ns myNamespace -g myResourceGroup --validity-days 30
Required Parameters
Name of the parent certificate authority.
Name of the certificate policy.
Name of the Device Registry namespace.
Name of resource group. You can configure the default group using az configure --defaults group=<name>.
Leaf certificate validity period in days. Must be between 1 and 90 days, inclusive.
Optional Parameters
The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.
Acquiring an Azure Policy token automatically for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
The related change reference ID for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
Location. Values from: az account list-locations. You can configure the default location using az configure --defaults location=<location>.
Do not wait for the long-running operation to finish.
| Property | Value |
|---|---|
| Default value: | False |
Space-separated tags: key[=value] [key[=value] ...]. Use "" to clear existing tags.
Global Parameters
Increase logging verbosity to show all debug logs.
| Property | Value |
|---|---|
| Default value: | False |
Show this help message and exit.
Only show errors, suppressing warnings.
| Property | Value |
|---|---|
| Default value: | False |
Output format.
| Property | Value |
|---|---|
| Default value: | json |
| Accepted values: | json, jsonc, none, table, tsv, yaml, yamlc |
JMESPath query string. See http://jmespath.org/ for more information and examples.
Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.
Increase logging verbosity. Use --debug for full debug logs.
| Property | Value |
|---|---|
| Default value: | False |
az iot adr ns ca policy delete
Command group 'iot adr ns ca policy' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
Delete a certificate policy from a certificate authority.
az iot adr ns ca policy delete --ca --ca-name
--name --pn --policy-name
--namespace --ns
--resource-group
[--acquire-policy-token]
[--change-reference]
[--no-wait]
[--yes {false, true}]
Examples
Delete a certificate policy
az iot adr ns ca policy delete -n myPolicy --ca-name myCA --ns myNamespace -g myResourceGroup
Required Parameters
Name of the parent certificate authority.
Name of the certificate policy.
Name of the Device Registry namespace.
Name of resource group. You can configure the default group using az configure --defaults group=<name>.
Optional Parameters
The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.
Acquiring an Azure Policy token automatically for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
The related change reference ID for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
Do not wait for the long-running operation to finish.
| Property | Value |
|---|---|
| Default value: | False |
Skip user prompts. Indicates acceptance of action. Used primarily for automation scenarios. Default: false.
| Property | Value |
|---|---|
| Accepted values: | false, true |
Global Parameters
Increase logging verbosity to show all debug logs.
| Property | Value |
|---|---|
| Default value: | False |
Show this help message and exit.
Only show errors, suppressing warnings.
| Property | Value |
|---|---|
| Default value: | False |
Output format.
| Property | Value |
|---|---|
| Default value: | json |
| Accepted values: | json, jsonc, none, table, tsv, yaml, yamlc |
JMESPath query string. See http://jmespath.org/ for more information and examples.
Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.
Increase logging verbosity. Use --debug for full debug logs.
| Property | Value |
|---|---|
| Default value: | False |
az iot adr ns ca policy list
Command group 'iot adr ns ca policy' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
List the certificate policies for a certificate authority.
az iot adr ns ca policy list --ca --ca-name
--namespace --ns
--resource-group
Examples
List certificate policies
az iot adr ns ca policy list --ca-name myCA --ns myNamespace -g myResourceGroup
Required Parameters
Name of the parent certificate authority.
Name of the Device Registry namespace.
Name of resource group. You can configure the default group using az configure --defaults group=<name>.
Global Parameters
Increase logging verbosity to show all debug logs.
| Property | Value |
|---|---|
| Default value: | False |
Show this help message and exit.
Only show errors, suppressing warnings.
| Property | Value |
|---|---|
| Default value: | False |
Output format.
| Property | Value |
|---|---|
| Default value: | json |
| Accepted values: | json, jsonc, none, table, tsv, yaml, yamlc |
JMESPath query string. See http://jmespath.org/ for more information and examples.
Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.
Increase logging verbosity. Use --debug for full debug logs.
| Property | Value |
|---|---|
| Default value: | False |
az iot adr ns ca policy show
Command group 'iot adr ns ca policy' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
Show a certificate policy for a certificate authority.
az iot adr ns ca policy show --ca --ca-name
--name --pn --policy-name
--namespace --ns
--resource-group
Examples
Show a certificate policy
az iot adr ns ca policy show -n myPolicy --ca-name myCA --ns myNamespace -g myResourceGroup
Required Parameters
Name of the parent certificate authority.
Name of the certificate policy.
Name of the Device Registry namespace.
Name of resource group. You can configure the default group using az configure --defaults group=<name>.
Global Parameters
Increase logging verbosity to show all debug logs.
| Property | Value |
|---|---|
| Default value: | False |
Show this help message and exit.
Only show errors, suppressing warnings.
| Property | Value |
|---|---|
| Default value: | False |
Output format.
| Property | Value |
|---|---|
| Default value: | json |
| Accepted values: | json, jsonc, none, table, tsv, yaml, yamlc |
JMESPath query string. See http://jmespath.org/ for more information and examples.
Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.
Increase logging verbosity. Use --debug for full debug logs.
| Property | Value |
|---|---|
| Default value: | False |
az iot adr ns ca policy update
Command group 'iot adr ns ca policy' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
Update a certificate policy for a certificate authority.
When supplied, the leaf certificate validity period must be between 1 and 90 days, inclusive.
az iot adr ns ca policy update --ca --ca-name
--name --pn --policy-name
--namespace --ns
--resource-group
[--acquire-policy-token]
[--change-reference]
[--no-wait]
[--tags]
[--validity-days --vd]
Examples
Update certificate policy tags
az iot adr ns ca policy update -n myPolicy --ca-name myCA --ns myNamespace -g myResourceGroup --tags env=prod
Update leaf certificate validity to the maximum supported period
az iot adr ns ca policy update -n myPolicy --ca-name myCA --ns myNamespace -g myResourceGroup --validity-days 90
Required Parameters
Name of the parent certificate authority.
Name of the certificate policy.
Name of the Device Registry namespace.
Name of resource group. You can configure the default group using az configure --defaults group=<name>.
Optional Parameters
The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.
Acquiring an Azure Policy token automatically for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
The related change reference ID for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
Do not wait for the long-running operation to finish.
| Property | Value |
|---|---|
| Default value: | False |
Space-separated tags: key[=value] [key[=value] ...]. Use "" to clear existing tags.
Updated leaf certificate validity period in days. Must be between 1 and 90 days, inclusive.
Global Parameters
Increase logging verbosity to show all debug logs.
| Property | Value |
|---|---|
| Default value: | False |
Show this help message and exit.
Only show errors, suppressing warnings.
| Property | Value |
|---|---|
| Default value: | False |
Output format.
| Property | Value |
|---|---|
| Default value: | json |
| Accepted values: | json, jsonc, none, table, tsv, yaml, yamlc |
JMESPath query string. See http://jmespath.org/ for more information and examples.
Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.
Increase logging verbosity. Use --debug for full debug logs.
| Property | Value |
|---|---|
| Default value: | False |
az iot adr ns ca policy wait
Command group 'iot adr ns ca policy' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
Wait for a certificate policy to reach a desired state.
Without an explicit wait predicate, waits for provisioningState Succeeded.
az iot adr ns ca policy wait --ca --ca-name
--name --pn --policy-name
--namespace --ns
--resource-group
[--acquire-policy-token]
[--change-reference]
[--created]
[--custom]
[--deleted]
[--exists]
[--interval]
[--timeout]
[--updated]
Examples
Wait until certificate policy provisioning succeeds
az iot adr ns ca policy wait -n myPolicy --ca-name myCA --ns myNamespace -g myResourceGroup
Required Parameters
Name of the parent certificate authority.
Name of the certificate policy.
Name of the Device Registry namespace.
Name of resource group. You can configure the default group using az configure --defaults group=<name>.
Optional Parameters
The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.
Acquiring an Azure Policy token automatically for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
The related change reference ID for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
Wait until provisioningState is Succeeded.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
| Default value: | False |
Wait until a custom JMESPath expression evaluates to true.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
Wait until the resource is deleted.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
| Default value: | False |
Wait until the resource exists.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
| Default value: | False |
Polling interval in seconds.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
| Default value: | 30 |
Polling budget in seconds, including GET time. An in-flight GET is bounded by transport timeouts and cannot be interrupted by this polling deadline.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
| Default value: | 3600 |
Wait until provisioningState is Succeeded.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
| Default value: | False |
Global Parameters
Increase logging verbosity to show all debug logs.
| Property | Value |
|---|---|
| Default value: | False |
Show this help message and exit.
Only show errors, suppressing warnings.
| Property | Value |
|---|---|
| Default value: | False |
Output format.
| Property | Value |
|---|---|
| Default value: | json |
| Accepted values: | json, jsonc, none, table, tsv, yaml, yamlc |
JMESPath query string. See http://jmespath.org/ for more information and examples.
Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.
Increase logging verbosity. Use --debug for full debug logs.
| Property | Value |
|---|---|
| Default value: | False |