Scroll to navigation

YUBIHSM-SHELL(1) User Commands YUBIHSM-SHELL(1)

NAME

yubihsm-shell - manual page for yubihsm-shell 2.6.0

SYNOPSIS

yubihsm-shell [OPTION]...

DESCRIPTION

Print help and exit
Print version and exit
Action to perform (possible values="benchmark", "blink-device", "create-otp-aead", "decrypt-aesccm", "decrypt-aescbc", "decrypt-aesecb", "decrypt-oaep", "decrypt-otp", "decrypt-pkcs1v15", "delete-object", "derive-ecdh", "encrypt-aesccm", "encrypt-aescbc", "encrypt-aesecb", "generate-asymmetric-key", "generate-hmac-key", "generate-otp-aead-key", "generate-wrap-key", "generate-symmetric-key", "get-device-info", "get-logs", "get-object-info", "get-opaque", "get-option", "get-pseudo-random", "get-public-key", "get-storage-info", "get-template", "get-wrapped", "get-rsa-wrapped", "get-rsa-wrapped-key", "get-device-pubkey", "list-objects", "put-asymmetric-key", "put-authentication-key", "put-hmac-key", "put-opaque", "put-option", "put-otp-aead-key", "put-symmetric-key", "put-template", "put-wrap-key", "put-rsa-wrapkey", "put-public-wrapkey", "put-wrapped", "put-rsa-wrapped", "put-rsa-wrapped-key", "randomize-otp-aead", "reset", "set-log-index", "sign-attestation-certificate", "sign-ecdsa", "sign-eddsa", "sign-hmac", "sign-pkcs1v15", "sign-pss", "sign-ssh-certificate")
Authentication password
Authentication key (default=`1')
Object ID (default=`0')
Object label (default=`')
Object domains (default=`1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16')
Capabilities for an object (default=`0')
Object type (default=`any')
Credential label on YubiKey (implicitly enables ykhsmauth)
(default=`')
Delegated capabilities (default=`0')
New authentication password
Operation algorithm (default=`any')
OAEP algorithm. Used primarily with asymmetric wrap (default=`rsa-oaep-sha256')
MGF1 algorithm. Used primarily with asymmetric wrap (default=`mgf1-sha256')
OTP nonce
An initialization vector as a hexadecimal string
Number of bytes to request (default=`256')
Blink duration in seconds (default=`10')
Wrap key ID
Include seed when exporting an ED25519 key under wrap (default=off)
Template ID
Attestation ID
Log index
Device option name
Device option value
Input data (filename) (default=`-')
Output data (filename) (default=`-')
Input format (possible values="default", "base64", "binary", "PEM", "password", "hex", "ASCII" default=`default')
Input and output format (possible values="default", "base64", "binary", "PEM", "hex", "ASCII" default=`default')
Configuration file to read (default=`')
List of connectors to use
HTTPS cacert for connector
HTTPS client certificate to authenticate with
HTTPS client certificate key
Proxy server to use for connector
Comma separated list of hosts ignore proxy for
Print more information (default=`0')
Connect immediately in interactive mode (default=off)
List of device public keys allowed for asymmetric authentication
December 2024 yubihsm-shell 2.6.0