Performs one or more of the following actions on the KMIP server object whose UUID is specified in the command.

--operation=<activate|archive|destroy|recover|revoke>

The action to perform on the KMIP object.

  • activate—By default, objects are created in PreActive state. Specify activate to enable more transitions for the object. Note: Many KMIP clients change objects to Active state as part of the creation process.
  • archive—Objects will no longer return keys but they remain in the system. You can use the recover operation to return an archived object to active state and retrieve its keys.
  • destroy—This operation permanently removes the object. Destroyed objects cannot be retrieved.
  • recover—Restores an Archived object to the active state so that its keys can be retrieved.
  • revoke—Revocation is permanent. Revoked objects cannot be moved back to Active, but the client can still retrieve any key material. You can also specify a revocation reason (any string) and a numeric Reason Code, which is one of the following KMIP standard codes. If you omit the reason code or use a non-standard code, it will be considered the same as "1—Unspecified."

    1. Unspecified

    2. Key Compromise

    3. CA Compromise

    4. Affiliation Changed

    5. Superseded

    6. Cessation of Operation

    7. Privilege Withdrawn

The following command activates a KMIP object:

$ hicli kmipsrv_obj action cd9e4370-e2cb-11e8-bdab-00505685b461 --operation=activate
success

The following commands archive and then restore a KMIP object, fetching details after each action to confirm the state changed correctly.

After you restore an object, the ArchiveDate is retained, but the Archived flag is no longer set.

$ hicli kmipsrv_obj action cd9e4370-e2cb-11e8-bdab-00505685b461 --operation=archive
success
$ hicli kmipsrv_obj fetch uuid=cd9e4370-e2cb-11e8-bdab-00505685b461
Archived : 1
CryptographicUsageMask : Decrypt Sign
InitialDate : 2018-11-07T20:29:19+00:00
State : Active
ActivationDate : 2018-11-09T20:22:18+00:00
ArchiveDate : 2018-11-09T20:27:05+00:00
CryptographicAlgorithm : RSA
LastChangeDate : 2018-11-09T20:27:05+00:00
CryptographicLength : 4096
ObjectType : PrivateKey
$ hicli kmipsrv_obj action cd9e4370-e2cb-11e8-bdab-00505685b461 --operation=restore
success
$ hicli kmipsrv_obj fetch uuid=cd9e4370-e2cb-11e8-bdab-00505685b461
CryptographicUsageMask : Decrypt Sign
InitialDate : 2018-11-07T20:29:19+00:00
State : Active
ActivationDate : 2018-11-09T20:22:18+00:00
ArchiveDate : 2018-11-09T20:27:05+00:00
CryptographicAlgorithm : RSA
LastChangeDate : 2018-11-09T20:27:05+00:00
CryptographicLength : 4096
ObjectType : PrivateKey

The following command revokes a KMIP object for the revocation reason "This key has been replaced with a new key".

$ hicli kmipsrv_obj action cd9e4370-e2cb-11e8-bdab-00505685b461 --operation=revoke --revcode=5
--revmsg='This key has been replaced with a new key'
success
$ hicli kmipsrv_obj fetch uuid=cd9e4370-e2cb-11e8-bdab-00505685b461
ActivationDate : 2018-11-09T20:22:18+00:00
RevocationReasonCode : Superceded
CryptographicUsageMask : Decrypt Sign
InitialDate : 2018-11-07T20:29:19+00:00
DeactivationDate : 2018-11-09T20:31:24+00:00
RevocationMessage : This key has been replaced with a new key
State : Deactivated
CryptographicAlgorithm : RSA
LastChangeDate : 2018-11-09T20:31:24+00:00
CryptographicLength : 4096
ObjectType : PrivateKey

--revcode=<revoke reason code>

If you are revoking the object, this is the standard KMIP reason code.

--revmsg=<revoke message>

If you are revoking the object, this is a user-defined string specifying the reason why you are revoking the object.

--desc=<description>

Sets the user-defined description for the object.