Use the Crypto CLI create-access-policy command to create a role-based access control policy to allow users or applications to access secrets.
Syntax
cryptocli create-access-policy [options]
Option | Description |
-h or --help | Displays usage text. |
-g or --ad-group stringArray | ||-separated string containing the DN & display name of AD groups to be added as principals. |
-L or --ad-logon-name stringArray | Logon name of AD users to be added as principals. This option is repeatable. |
-u or --ad-upn stringArray | The UPN of AD users to be added as principals. This option is repeatable. |
-l or --local-user stringArray | Local username of users to be added as principals. This option is repeatable. |
-n or --name string | The name of the policy. Strings must be enclosed in double quotes. |
-p or –-tokenization_permissions stringArray | Tokenization permissions for users of this policy. This option is repeatable. |
-r or --role string | The role of the user that is being assigned. |
-t or --tagkey stringArray | The tag key to associate with the policy. This option is repeatable. |
-v or --tagvalue stringArray | The tag value to associate with the policy. This option is repeatable. |