az iot adr ns ca policy

Note

This reference is part of the azure-iot extension for the Azure CLI (version 2.73.0 or higher). The extension will automatically install the first time you run an az iot adr ns ca policy command. Learn more about extensions.

Command group 'iot adr ns ca' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Manage certificate policies for a certificate authority.

A certificate policy carries the leaf certificate issuance settings for a certificate authority.

Commands

Name Description Type Status
az iot adr ns ca policy create

Create a certificate policy for a certificate authority.

Extension Preview
az iot adr ns ca policy delete

Delete a certificate policy from a certificate authority.

Extension Preview
az iot adr ns ca policy list

List the certificate policies for a certificate authority.

Extension Preview
az iot adr ns ca policy show

Show a certificate policy for a certificate authority.

Extension Preview
az iot adr ns ca policy update

Update a certificate policy for a certificate authority.

Extension Preview
az iot adr ns ca policy wait

Wait for a certificate policy to reach a desired state.

Extension Preview

az iot adr ns ca policy create

Preview

Command group 'iot adr ns ca policy' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Create a certificate policy for a certificate authority.

Certificate policies can only be created under an issuing certificate authority with type ICA. Create the ICA under a Root CA, then pass the ICA name to --ca-name. The leaf certificate validity period must be between 1 and 90 days, inclusive. Use 'ca policy update --validity-days' to change the validity period of an existing policy.

az iot adr ns ca policy create --ca --ca-name
                               --name --pn --policy-name
                               --namespace --ns
                               --resource-group
                               --validity-days --vd
                               [--acquire-policy-token]
                               [--change-reference]
                               [--location]
                               [--no-wait]
                               [--tags]

Examples

Create a certificate policy with a 30 day leaf certificate validity period

az iot adr ns ca policy create -n myPolicy --ca-name myICA --ns myNamespace -g myResourceGroup --validity-days 30

Required Parameters

--ca --ca-name

Name of the parent certificate authority.

--name --pn --policy-name -n

Name of the certificate policy.

--namespace --ns

Name of the Device Registry namespace.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

--validity-days --vd

Leaf certificate validity period in days. Must be between 1 and 90 days, inclusive.

Optional Parameters

The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.

--acquire-policy-token

Acquiring an Azure Policy token automatically for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--change-reference

The related change reference ID for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--location -l

Location. Values from: az account list-locations. You can configure the default location using az configure --defaults location=<location>.

--no-wait

Do not wait for the long-running operation to finish.

Property Value
Default value: False
--tags

Space-separated tags: key[=value] [key[=value] ...]. Use "" to clear existing tags.

Global Parameters
--debug

Increase logging verbosity to show all debug logs.

Property Value
Default value: False
--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

Property Value
Default value: False
--output -o

Output format.

Property Value
Default value: json
Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

Property Value
Default value: False

az iot adr ns ca policy delete

Preview

Command group 'iot adr ns ca policy' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Delete a certificate policy from a certificate authority.

az iot adr ns ca policy delete --ca --ca-name
                               --name --pn --policy-name
                               --namespace --ns
                               --resource-group
                               [--acquire-policy-token]
                               [--change-reference]
                               [--no-wait]
                               [--yes {false, true}]

Examples

Delete a certificate policy

az iot adr ns ca policy delete -n myPolicy --ca-name myCA --ns myNamespace -g myResourceGroup

Required Parameters

--ca --ca-name

Name of the parent certificate authority.

--name --pn --policy-name -n

Name of the certificate policy.

--namespace --ns

Name of the Device Registry namespace.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

Optional Parameters

The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.

--acquire-policy-token

Acquiring an Azure Policy token automatically for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--change-reference

The related change reference ID for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--no-wait

Do not wait for the long-running operation to finish.

Property Value
Default value: False
--yes -y

Skip user prompts. Indicates acceptance of action. Used primarily for automation scenarios. Default: false.

Property Value
Accepted values: false, true
Global Parameters
--debug

Increase logging verbosity to show all debug logs.

Property Value
Default value: False
--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

Property Value
Default value: False
--output -o

Output format.

Property Value
Default value: json
Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

Property Value
Default value: False

az iot adr ns ca policy list

Preview

Command group 'iot adr ns ca policy' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

List the certificate policies for a certificate authority.

az iot adr ns ca policy list --ca --ca-name
                             --namespace --ns
                             --resource-group

Examples

List certificate policies

az iot adr ns ca policy list --ca-name myCA --ns myNamespace -g myResourceGroup

Required Parameters

--ca --ca-name

Name of the parent certificate authority.

--namespace --ns

Name of the Device Registry namespace.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

Global Parameters
--debug

Increase logging verbosity to show all debug logs.

Property Value
Default value: False
--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

Property Value
Default value: False
--output -o

Output format.

Property Value
Default value: json
Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

Property Value
Default value: False

az iot adr ns ca policy show

Preview

Command group 'iot adr ns ca policy' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Show a certificate policy for a certificate authority.

az iot adr ns ca policy show --ca --ca-name
                             --name --pn --policy-name
                             --namespace --ns
                             --resource-group

Examples

Show a certificate policy

az iot adr ns ca policy show -n myPolicy --ca-name myCA --ns myNamespace -g myResourceGroup

Required Parameters

--ca --ca-name

Name of the parent certificate authority.

--name --pn --policy-name -n

Name of the certificate policy.

--namespace --ns

Name of the Device Registry namespace.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

Global Parameters
--debug

Increase logging verbosity to show all debug logs.

Property Value
Default value: False
--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

Property Value
Default value: False
--output -o

Output format.

Property Value
Default value: json
Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

Property Value
Default value: False

az iot adr ns ca policy update

Preview

Command group 'iot adr ns ca policy' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Update a certificate policy for a certificate authority.

When supplied, the leaf certificate validity period must be between 1 and 90 days, inclusive.

az iot adr ns ca policy update --ca --ca-name
                               --name --pn --policy-name
                               --namespace --ns
                               --resource-group
                               [--acquire-policy-token]
                               [--change-reference]
                               [--no-wait]
                               [--tags]
                               [--validity-days --vd]

Examples

Update certificate policy tags

az iot adr ns ca policy update -n myPolicy --ca-name myCA --ns myNamespace -g myResourceGroup --tags env=prod

Update leaf certificate validity to the maximum supported period

az iot adr ns ca policy update -n myPolicy --ca-name myCA --ns myNamespace -g myResourceGroup --validity-days 90

Required Parameters

--ca --ca-name

Name of the parent certificate authority.

--name --pn --policy-name -n

Name of the certificate policy.

--namespace --ns

Name of the Device Registry namespace.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

Optional Parameters

The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.

--acquire-policy-token

Acquiring an Azure Policy token automatically for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--change-reference

The related change reference ID for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--no-wait

Do not wait for the long-running operation to finish.

Property Value
Default value: False
--tags

Space-separated tags: key[=value] [key[=value] ...]. Use "" to clear existing tags.

--validity-days --vd

Updated leaf certificate validity period in days. Must be between 1 and 90 days, inclusive.

Global Parameters
--debug

Increase logging verbosity to show all debug logs.

Property Value
Default value: False
--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

Property Value
Default value: False
--output -o

Output format.

Property Value
Default value: json
Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

Property Value
Default value: False

az iot adr ns ca policy wait

Preview

Command group 'iot adr ns ca policy' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Wait for a certificate policy to reach a desired state.

Without an explicit wait predicate, waits for provisioningState Succeeded.

az iot adr ns ca policy wait --ca --ca-name
                             --name --pn --policy-name
                             --namespace --ns
                             --resource-group
                             [--acquire-policy-token]
                             [--change-reference]
                             [--created]
                             [--custom]
                             [--deleted]
                             [--exists]
                             [--interval]
                             [--timeout]
                             [--updated]

Examples

Wait until certificate policy provisioning succeeds

az iot adr ns ca policy wait -n myPolicy --ca-name myCA --ns myNamespace -g myResourceGroup

Required Parameters

--ca --ca-name

Name of the parent certificate authority.

--name --pn --policy-name -n

Name of the certificate policy.

--namespace --ns

Name of the Device Registry namespace.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

Optional Parameters

The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.

--acquire-policy-token

Acquiring an Azure Policy token automatically for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--change-reference

The related change reference ID for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--created

Wait until provisioningState is Succeeded.

Property Value
Parameter group: Wait Condition Arguments
Default value: False
--custom

Wait until a custom JMESPath expression evaluates to true.

Property Value
Parameter group: Wait Condition Arguments
--deleted

Wait until the resource is deleted.

Property Value
Parameter group: Wait Condition Arguments
Default value: False
--exists

Wait until the resource exists.

Property Value
Parameter group: Wait Condition Arguments
Default value: False
--interval

Polling interval in seconds.

Property Value
Parameter group: Wait Condition Arguments
Default value: 30
--timeout

Polling budget in seconds, including GET time. An in-flight GET is bounded by transport timeouts and cannot be interrupted by this polling deadline.

Property Value
Parameter group: Wait Condition Arguments
Default value: 3600
--updated

Wait until provisioningState is Succeeded.

Property Value
Parameter group: Wait Condition Arguments
Default value: False
Global Parameters
--debug

Increase logging verbosity to show all debug logs.

Property Value
Default value: False
--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

Property Value
Default value: False
--output -o

Output format.

Property Value
Default value: json
Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

Property Value
Default value: False