Skip to main content

List of Key-Management Actions

Following table lists key management actions available through the Key Manager GUI. It lists the name of the action, its corresponding command-line client command, and a brief description of what the action does.

Unless otherwise stated, you can perform actions on objects via the following pages of the Key Manager GUI:

  • Users: User Keys→Users

  • Authorized keys: User Keys→Authorized Keys

  • Private keys: User Keys→Private Keys

  • Authorizations: User Keys→Authorizations

Table 10.1. Key-Management Actions
ActionCommand-line client commandDescription
Add Authorization From/Toadd-\
authorizations
Add the selected user(s) to the list of authorization sources or destinations on the Home→Add Authorizations page. For more information about adding authorizations, see Adding Authorizations
Approveapprove-\
authorized-keys
approve-private-\
keys
Convert appeared authorized or private keys to present keys to signify that the key in question has been reviewed and approved as a trusted key in the managed environment.
Blacklistblacklist-\
authorized-keys
The target authorized or private key(s), and any key with corresponding fingerprint(s) are automatically deleted, and entries matching to these keys are marked as blacklisted. For more information about blacklisting, see Blacklisting User Keys.
Edit Custom Fieldsmodify-\
authorized-key
modify-private-\
key
modify-user
Associate custom phrases to target user keys, authorizations and users, which helps searching and managing them.
Export Public Keylist-authorized-\
keys
list-private-keys
For a public key, display the target-key data. For a private key, display the data of its associated public key. For more information about exporting public key data, see Exporting Public-Key Data.
Forget Passphraseforget-private-\
key-passphrase
Remove target private key(s') passphrase(s) from Key Manager. For more information about managing passphrases, see Managing User-Key Passphrases.
Managemanage-authorized\
-keys
manage-private-\
keys
Convert legacy keys, and unmanaged keys to managed keys to signify that the key in question has been reviewed and approved as a trusted key in the managed environment.
Note When you convert a user key to a managed key, all keys with the same fingerprint are also converted to the managed state. This includes both the private and the corresponding authorized keys.
Provide Passphraseprovide-private-\
key-passphrase
Provide an unknown passphrase of a private key to be stored by the Key Manager. For more information about managing passphrases, see Managing User-Key Passphrases.
Register External Private Keyregister-external\
-private-key
Manually add information to an authorization with an unknown private-key component. Key Manager creates an external-private-key entry based on the provided information and associates it to the authorization entries that share the same fingerprint.
Removeremove-authorized\
-keys
remove-private-\
keys
Remove the target user key(s).
Renewrenew-private-keysReplace selected private key(s) and all corresponding authorized keys with newly generated keys as soon as possible. For more information about key renewal, see Renewing Authorizations.
Restorerestore-\
authorized-keys
restore-private-\
keys
Restore removed or missing authorized keys, and removed private keys.

Removed private keys can only be restored if you have enabled private-key backups. For more information about backup settings, see Host Settings.
RollbackRevert user-key changes caused by key-management actions, as well as changes detected via host scans. For more information, see Roll Back Changes to User Keys.
Set Labellabel-host-keys
label-authorized-\
keys
label-fingerprints
label-private-keys
Give a label to the target key(s) or authorization(s). Maximum length 100 characters.
Set NotesAdd notes to target key(s).
Set Optionsadd-authorized-\
key-options
remove-authorized\
-key-options
set-authorized-\
key-options
update-authorized\
-key-options
Specify options such as where authorizations can be used from, and what the authorization can be used to run. This can be performed on authorized keys. For more information about setting options, see Setting Options for Authorized Keys
Set Passphraseset-private-key-\
passphrase
Give the selected private key a passphrase in Key Manager. For more information about managing passphrases, see Managing User-Key Passphrases.
Set ValiditySet the validity period of the selected authorized key(s).
Show PassphraseDisplay the target private-key passphrase.
Sign-off: Accept/Rejectsignoff-accept-\
authorized-key
signoff-reject-\
authorized-key
Perform signoff and accept or reject the target user key(s). For more information about the key-sign workflow, see the PrivX Key Manager User Portal Manuals
Tagtag-users
tag-authorized-\
keys
tag-private-keys
untag-users
untag-authorized-\
keys
untag-private-keys
Add or remove tags from users and user keys, for search and management purposes.
View Audit HistoryView audit-event logs related to the target user, key or authorization. For more information about audit events, see Auditing, Alerting, and Reporting.