az iot adr ns ca
Note
This reference is part of the azure-iot extension for the Azure CLI (version 2.73.0 or higher). The extension will automatically install the first time you run an az iot adr ns ca command. Learn more about extensions.
Command group 'iot adr ns' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
Manage certificate authorities for a Device Registry namespace.
Commands
| Name | Description | Type | Status |
|---|---|---|---|
| az iot adr ns ca activate |
Activate an externally issued intermediate certificate authority. |
Extension | Preview |
| az iot adr ns ca create |
Create a certificate authority for a Device Registry namespace. |
Extension | Preview |
| az iot adr ns ca delete |
Delete a certificate authority from a Device Registry namespace. |
Extension | Preview |
| az iot adr ns ca list |
List the certificate authorities for a Device Registry namespace. |
Extension | Preview |
| az iot adr ns ca policy |
Manage certificate policies for a certificate authority. |
Extension | Preview |
| az iot adr ns ca policy create |
Create a certificate policy for a certificate authority. |
Extension | Preview |
| az iot adr ns ca policy delete |
Delete a certificate policy from a certificate authority. |
Extension | Preview |
| az iot adr ns ca policy list |
List the certificate policies for a certificate authority. |
Extension | Preview |
| az iot adr ns ca policy show |
Show a certificate policy for a certificate authority. |
Extension | Preview |
| az iot adr ns ca policy update |
Update a certificate policy for a certificate authority. |
Extension | Preview |
| az iot adr ns ca policy wait |
Wait for a certificate policy to reach a desired state. |
Extension | Preview |
| az iot adr ns ca revoke |
Revoke and rotate an intermediate certificate authority issued by a Microsoft CA. |
Extension | Preview |
| az iot adr ns ca show |
Show a certificate authority for a Device Registry namespace. |
Extension | Preview |
| az iot adr ns ca update |
Update a certificate authority for a Device Registry namespace. |
Extension | Preview |
| az iot adr ns ca wait |
Wait for a certificate authority to reach a desired state. |
Extension | Preview |
az iot adr ns ca activate
Command group 'iot adr ns ca' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
Activate an externally issued intermediate certificate authority.
Use this after creating an ICA with --issuer-type External and signing the service-generated CSR with your external PKI. The certificate chain file must be in PEM format with certificates ordered from leaf to root. Sign the actual service CSR and preserve its requested extensions. OpenSSL x509 -req does not copy them by default: the recipe below requires an OpenSSL version supporting -copy_extensions copy and req -addext. Protect the external root private key; use this disposable test root only for testing. Remaining validity is measured at activation. Activation may be rejected when less than 365 days of validity remain, so allow margin and make sure the root covers the ICA's entire validity. Keep the extensions requested in the CSR. The CLI checks common certificate defects; the service does final validation. Without --no-wait, returns the CA once it is Active.
az iot adr ns ca activate --ca-name --name
--ccf --certificate-chain-file
--namespace --ns
--resource-group
[--acquire-policy-token]
[--change-reference]
[--no-wait]
Examples
Activate an externally issued ICA
az iot adr ns ca activate -n myExternalICA --ns myNamespace -g myResourceGroup --certificate-chain-file ./signed-chain.pem
Create a disposable ECC root, sign the service CSR, and activate (Bash; supported OpenSSL required)
(
set -eu
umask 077
pki=$(mktemp -d)
trap 'rm -f "$pki/root.key" "$pki/root.pem" "$pki/ica.csr" "$pki/ica.pem" "$pki/chain.pem"; rmdir "$pki"' EXIT
openssl req -x509 -newkey ec -pkeyopt ec_paramgen_curve:secp384r1 -nodes \
-keyout "$pki/root.key" -out "$pki/root.pem" -days 3650 -subj "/CN=Disposable ADR Root" \
-addext "basicConstraints=critical,CA:TRUE,pathlen:2" \
-addext "keyUsage=critical,keyCertSign,cRLSign"
az iot adr ns ca create -n myExternalICA --ns myNamespace -g myResourceGroup \
--type ICA --issuer-type External --key-type ECC
az iot adr ns ca show -n myExternalICA --ns myNamespace -g myResourceGroup \
--query properties.issuer.certificateSigningRequest -o tsv > "$pki/ica.csr"
openssl req -in "$pki/ica.csr" -noout -text
openssl x509 -req -in "$pki/ica.csr" -CA "$pki/root.pem" -CAkey "$pki/root.key" \
-set_serial 2 -days 730 -sha384 -copy_extensions copy -out "$pki/ica.pem"
cat "$pki/ica.pem" "$pki/root.pem" > "$pki/chain.pem"
az iot adr ns ca activate -n myExternalICA --ns myNamespace -g myResourceGroup \
--certificate-chain-file "$pki/chain.pem"
)
Required Parameters
Name of the certificate authority.
Path to a PEM file containing the signed certificate chain for an externally issued ICA. Certificates must be ordered from leaf to root, match the service CSR key, and preserve requested extensions. Allow remaining-validity margin at activation; see activate help for the OpenSSL recipe and observed service constraints.
Name of the Device Registry namespace.
Name of resource group. You can configure the default group using az configure --defaults group=<name>.
Optional Parameters
The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.
Acquiring an Azure Policy token automatically for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
The related change reference ID for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
Do not wait for the long-running operation to finish.
| Property | Value |
|---|---|
| Default value: | False |
Global Parameters
Increase logging verbosity to show all debug logs.
| Property | Value |
|---|---|
| Default value: | False |
Show this help message and exit.
Only show errors, suppressing warnings.
| Property | Value |
|---|---|
| Default value: | False |
Output format.
| Property | Value |
|---|---|
| Default value: | json |
| Accepted values: | json, jsonc, none, table, tsv, yaml, yamlc |
JMESPath query string. See http://jmespath.org/ for more information and examples.
Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.
Increase logging verbosity. Use --debug for full debug logs.
| Property | Value |
|---|---|
| Default value: | False |
az iot adr ns ca create
Command group 'iot adr ns ca' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
Create a certificate authority for a Device Registry namespace.
The certificate authority type determines the required associated properties:
- Root: a service-managed self-signed root CA.
- ICA with a Microsoft issuer: signed by a root CA in the same namespace. Pass the issuing CA's name with --issuer-ca-name.
- ICA with an External issuer: signed by an external PKI. After creation the service returns a CSR; sign that CSR (do not generate a replacement ICA key) and complete activation with 'az iot adr ns ca activate'. See activate help for a complete external ECC signing recipe.
az iot adr ns ca create --ca-name --name
--ca-type --type {ICA, Root}
--namespace --ns
--resource-group
[--acquire-policy-token]
[--change-reference]
[--issuer-ca-name --issuer-certificate-authority-name]
[--issuer-type {External, Microsoft}]
[--key-type {ECC}]
[--location]
[--no-wait]
[--tags]
Examples
Create a service-managed root certificate authority
az iot adr ns ca create -n myRootCA --ns myNamespace -g myResourceGroup --type Root
Create a Microsoft-issued intermediate certificate authority
az iot adr ns ca create -n myMicrosoftICA --ns myNamespace -g myResourceGroup \
--type ICA --issuer-type Microsoft --issuer-ca-name myRootCA
Create an externally issued intermediate certificate authority
az iot adr ns ca create -n myExternalICA --ns myNamespace -g myResourceGroup \
--type ICA --issuer-type External
Required Parameters
Name of the certificate authority.
The certificate authority type. Use 'Root' for a service-managed self-signed root CA or 'ICA' for an intermediate CA.
| Property | Value |
|---|---|
| Accepted values: | ICA, Root |
Name of the Device Registry namespace.
Name of resource group. You can configure the default group using az configure --defaults group=<name>.
Optional Parameters
The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.
Acquiring an Azure Policy token automatically for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
The related change reference ID for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
Name of the same-namespace issuing root CA. Required with --issuer-type Microsoft.
Issuer type for an ICA. Use 'Microsoft' for a same-namespace CA or 'External' for an external PKI.
| Property | Value |
|---|---|
| Accepted values: | External, Microsoft |
The cryptographic key type for the certificate authority.
| Property | Value |
|---|---|
| Accepted values: | ECC |
Location. Values from: az account list-locations. You can configure the default location using az configure --defaults location=<location>.
Do not wait for the long-running operation to finish.
| Property | Value |
|---|---|
| Default value: | False |
Space-separated tags: key[=value] [key[=value] ...]. Use "" to clear existing tags.
Global Parameters
Increase logging verbosity to show all debug logs.
| Property | Value |
|---|---|
| Default value: | False |
Show this help message and exit.
Only show errors, suppressing warnings.
| Property | Value |
|---|---|
| Default value: | False |
Output format.
| Property | Value |
|---|---|
| Default value: | json |
| Accepted values: | json, jsonc, none, table, tsv, yaml, yamlc |
JMESPath query string. See http://jmespath.org/ for more information and examples.
Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.
Increase logging verbosity. Use --debug for full debug logs.
| Property | Value |
|---|---|
| Default value: | False |
az iot adr ns ca delete
Command group 'iot adr ns ca' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
Delete a certificate authority from a Device Registry namespace.
az iot adr ns ca delete --ca-name --name
--namespace --ns
--resource-group
[--acquire-policy-token]
[--change-reference]
[--no-wait]
[--yes {false, true}]
Examples
Delete a certificate authority
az iot adr ns ca delete -n myCA --ns myNamespace -g myResourceGroup
Required Parameters
Name of the certificate authority.
Name of the Device Registry namespace.
Name of resource group. You can configure the default group using az configure --defaults group=<name>.
Optional Parameters
The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.
Acquiring an Azure Policy token automatically for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
The related change reference ID for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
Do not wait for the long-running operation to finish.
| Property | Value |
|---|---|
| Default value: | False |
Skip user prompts. Indicates acceptance of action. Used primarily for automation scenarios. Default: false.
| Property | Value |
|---|---|
| Accepted values: | false, true |
Global Parameters
Increase logging verbosity to show all debug logs.
| Property | Value |
|---|---|
| Default value: | False |
Show this help message and exit.
Only show errors, suppressing warnings.
| Property | Value |
|---|---|
| Default value: | False |
Output format.
| Property | Value |
|---|---|
| Default value: | json |
| Accepted values: | json, jsonc, none, table, tsv, yaml, yamlc |
JMESPath query string. See http://jmespath.org/ for more information and examples.
Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.
Increase logging verbosity. Use --debug for full debug logs.
| Property | Value |
|---|---|
| Default value: | False |
az iot adr ns ca list
Command group 'iot adr ns ca' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
List the certificate authorities for a Device Registry namespace.
az iot adr ns ca list --namespace --ns
--resource-group
Examples
List certificate authorities
az iot adr ns ca list --ns myNamespace -g myResourceGroup
Required Parameters
Name of the Device Registry namespace.
Name of resource group. You can configure the default group using az configure --defaults group=<name>.
Global Parameters
Increase logging verbosity to show all debug logs.
| Property | Value |
|---|---|
| Default value: | False |
Show this help message and exit.
Only show errors, suppressing warnings.
| Property | Value |
|---|---|
| Default value: | False |
Output format.
| Property | Value |
|---|---|
| Default value: | json |
| Accepted values: | json, jsonc, none, table, tsv, yaml, yamlc |
JMESPath query string. See http://jmespath.org/ for more information and examples.
Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.
Increase logging verbosity. Use --debug for full debug logs.
| Property | Value |
|---|---|
| Default value: | False |
az iot adr ns ca revoke
Command group 'iot adr ns ca' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
Revoke and rotate an intermediate certificate authority issued by a Microsoft CA.
Applies only to an ICA whose issuerType is 'Microsoft'. The service revokes the current certificate and issues a replacement signed by the same root CA. Successful waited revocation returns a fresh CA resource; --no-wait returns submission only without an added completion wait or output read. Microsoft issuers may not expose status or thumbprint. Fields are returned as supplied by the service. provisioningState describes the resource operation; it does not prove that an old certificate is rejected.
az iot adr ns ca revoke --ca-name --name
--namespace --ns
--resource-group
[--acquire-policy-token]
[--change-reference]
[--no-wait]
[--yes {false, true}]
Examples
Revoke a certificate authority
az iot adr ns ca revoke -n myCA --ns myNamespace -g myResourceGroup
Required Parameters
Name of the certificate authority.
Name of the Device Registry namespace.
Name of resource group. You can configure the default group using az configure --defaults group=<name>.
Optional Parameters
The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.
Acquiring an Azure Policy token automatically for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
The related change reference ID for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
Do not wait for the long-running operation to finish.
| Property | Value |
|---|---|
| Default value: | False |
Skip user prompts. Indicates acceptance of action. Used primarily for automation scenarios. Default: false.
| Property | Value |
|---|---|
| Accepted values: | false, true |
Global Parameters
Increase logging verbosity to show all debug logs.
| Property | Value |
|---|---|
| Default value: | False |
Show this help message and exit.
Only show errors, suppressing warnings.
| Property | Value |
|---|---|
| Default value: | False |
Output format.
| Property | Value |
|---|---|
| Default value: | json |
| Accepted values: | json, jsonc, none, table, tsv, yaml, yamlc |
JMESPath query string. See http://jmespath.org/ for more information and examples.
Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.
Increase logging verbosity. Use --debug for full debug logs.
| Property | Value |
|---|---|
| Default value: | False |
az iot adr ns ca show
Command group 'iot adr ns ca' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
Show a certificate authority for a Device Registry namespace.
az iot adr ns ca show --ca-name --name
--namespace --ns
--resource-group
Examples
Show a certificate authority
az iot adr ns ca show -n myCA --ns myNamespace -g myResourceGroup
Required Parameters
Name of the certificate authority.
Name of the Device Registry namespace.
Name of resource group. You can configure the default group using az configure --defaults group=<name>.
Global Parameters
Increase logging verbosity to show all debug logs.
| Property | Value |
|---|---|
| Default value: | False |
Show this help message and exit.
Only show errors, suppressing warnings.
| Property | Value |
|---|---|
| Default value: | False |
Output format.
| Property | Value |
|---|---|
| Default value: | json |
| Accepted values: | json, jsonc, none, table, tsv, yaml, yamlc |
JMESPath query string. See http://jmespath.org/ for more information and examples.
Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.
Increase logging verbosity. Use --debug for full debug logs.
| Property | Value |
|---|---|
| Default value: | False |
az iot adr ns ca update
Command group 'iot adr ns ca' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
Update a certificate authority for a Device Registry namespace.
az iot adr ns ca update --ca-name --name
--namespace --ns
--resource-group
[--acquire-policy-token]
[--change-reference]
[--no-wait]
[--tags]
Examples
Update certificate authority tags
az iot adr ns ca update -n myCA --ns myNamespace -g myResourceGroup --tags env=prod
Required Parameters
Name of the certificate authority.
Name of the Device Registry namespace.
Name of resource group. You can configure the default group using az configure --defaults group=<name>.
Optional Parameters
The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.
Acquiring an Azure Policy token automatically for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
The related change reference ID for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
Do not wait for the long-running operation to finish.
| Property | Value |
|---|---|
| Default value: | False |
Space-separated tags: key[=value] [key[=value] ...]. Use "" to clear existing tags.
Global Parameters
Increase logging verbosity to show all debug logs.
| Property | Value |
|---|---|
| Default value: | False |
Show this help message and exit.
Only show errors, suppressing warnings.
| Property | Value |
|---|---|
| Default value: | False |
Output format.
| Property | Value |
|---|---|
| Default value: | json |
| Accepted values: | json, jsonc, none, table, tsv, yaml, yamlc |
JMESPath query string. See http://jmespath.org/ for more information and examples.
Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.
Increase logging verbosity. Use --debug for full debug logs.
| Property | Value |
|---|---|
| Default value: | False |
az iot adr ns ca wait
Command group 'iot adr ns ca' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
Wait for a certificate authority to reach a desired state.
Without an explicit wait predicate, waits for provisioningState Succeeded.
az iot adr ns ca wait --ca-name --name
--namespace --ns
--resource-group
[--acquire-policy-token]
[--change-reference]
[--created]
[--custom]
[--deleted]
[--exists]
[--interval]
[--timeout]
[--updated]
Examples
Wait until certificate authority provisioning succeeds
az iot adr ns ca wait -n myCA --ns myNamespace -g myResourceGroup
Required Parameters
Name of the certificate authority.
Name of the Device Registry namespace.
Name of resource group. You can configure the default group using az configure --defaults group=<name>.
Optional Parameters
The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.
Acquiring an Azure Policy token automatically for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
The related change reference ID for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
Wait until provisioningState is Succeeded.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
| Default value: | False |
Wait until a custom JMESPath expression evaluates to true.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
Wait until the resource is deleted.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
| Default value: | False |
Wait until the resource exists.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
| Default value: | False |
Polling interval in seconds.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
| Default value: | 30 |
Polling budget in seconds, including GET time. An in-flight GET is bounded by transport timeouts and cannot be interrupted by this polling deadline.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
| Default value: | 3600 |
Wait until provisioningState is Succeeded.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
| Default value: | False |
Global Parameters
Increase logging verbosity to show all debug logs.
| Property | Value |
|---|---|
| Default value: | False |
Show this help message and exit.
Only show errors, suppressing warnings.
| Property | Value |
|---|---|
| Default value: | False |
Output format.
| Property | Value |
|---|---|
| Default value: | json |
| Accepted values: | json, jsonc, none, table, tsv, yaml, yamlc |
JMESPath query string. See http://jmespath.org/ for more information and examples.
Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.
Increase logging verbosity. Use --debug for full debug logs.
| Property | Value |
|---|---|
| Default value: | False |