LunaSH Command Summary

This section provides a summary of all of the LunaSH commands, and which users are able to access the commands.

The standard administrative LunaSH user accounts on the SafeNet Luna Network HSM appliance are:

admin All commands, except some specialized audit commands. This is the highest-level, full-access administrative role.
operator Most commands, except some configuration commands for the system and the HSM.
monitor Only commands that present information about the appliance or the HSM.
audit Only commands governing HSM audit logging functions.

When you log into the appliance as one of the standard users (or a custom user assigned one of the standard roles), you are able to access the subset of commands listed in the relevant column below. You can also create custom user roles and specify the list of commands that user role is able to access (see Appliance Users and Roles).

Some commands are restricted to the HSM SO or Auditor; these will not work until you log in to the HSM using hsm login or audit login.

NOTE   The commands marked "configurable" do not require hsm login by default. You can use sysconf forcesologin enable to require hsm login for these commands (see sysconf forcesologin).

Command admin operator monitor audit hsm or audit
login required
exit  
help  
audit
audit changepwd        
audit config      
audit init        
audit log clear        
audit log list        
audit log tail        
audit log tarlogs        
audit log untarlogs        
audit log verify        
audit login        
audit logout      
audit remotehost add        
audit remotehost clear        
audit remotehost delete        
audit remotehost list        
audit secret export      
audit secret import      
audit show        
audit sync      
client
client assignpartition     configurable
client delete     configurable
client fingerprint      
client hostip map     configurable
client hostip show    
client hostip unmap     configurable
client list    
client register     configurable
client revokepartition     configurable
client show    
hsm
hsm backup      
hsm changepolicy      
hsm changepw        
hsm checkcertificates    
hsm displaylicenses    
hsm factoryreset        
hsm firmware rollback    
hsm firmware show    
hsm firmware upgrade    
hsm fm delete      
hsm fm load      
hsm fm recover      
hsm fm smfs activate      
hsm fm status        
hsm generatedak      
hsm information monitor    
hsm information reset      
hsm information show    
hsm init        
hsm loadcustomercert      
hsm login      
hsm logout    
hsm ped connect    
hsm ped deselect    
hsm ped disconnect    
hsm ped select    
hsm ped server delete        
hsm ped server list    
hsm ped server register        
hsm ped set        
hsm ped show  
hsm ped timeout set    
hsm ped timeout show  
hsm ped vector erase        
hsm ped vector init      
hsm qos metrics reset      
hsm qos metrics show      
hsm restore    
hsm selftest    
hsm setlegacydomain        
hsm show    
hsm showpolicies  
hsm stc activationtimeout set      
hsm stc activationtimeout show      
hsm stc cipher disable      
hsm stc cipher enable      
hsm stc cipher show      
hsm stc disable      
hsm stc enable      
hsm stc hmac disable      
hsm stc hmac enable      
hsm stc hmac show      
hsm stc identity create      
hsm stc identity delete      
hsm stc identity initialize      
hsm stc identity partition deregister      
hsm stc identity partition register      
hsm stc identity show      
hsm stc partition export    
hsm stc partition show      
hsm stc rekeythreshold set    
hsm stc rekeythreshold show      
hsm stc status    
hsm stm recover    
hsm stm show    
hsm stm transport    
hsm supportinfo    
hsm tamper clear      
hsm tamper show    
hsm update capability      
hsm update show      
hsm zeroize        
my
my file clear  
my file delete  
my file list  
my password expiry show  
my password set  
my public-key add  
my public-key clear  
my public-key delete  
my public-key list  
network
network dns add nameserver      
network dns add searchdomain      
network dns delete nameserver      
network dns delete searchdomain      
network hostname      
network interface bonding config      
network interface bonding disable      
network interface bonding enable      
network interface bonding show    
network interface delete      
network interface dhcp      
network interface slaac      
network interface static      
network ping  
network route add      
network route clear      
network route delete      
network route show    
network show  
ntls
ntls bind     configurable
ntls certificate monitor disable     configurable
ntls certificate monitor enable     configurable
ntls certificate monitor show    
ntls certificate monitor trap trigger     configurable
ntls certificate show    
ntls information reset     configurable
ntls information show    
ntls ipcheck disable     configurable
ntls ipcheck enable     configurable
ntls ipcheck show    
ntls show    
ntls tcp_keepalive set     configurable
ntls tcp_keepalive show    
ntls threads set     configurable
ntls threads show    
ntls timer set     configurable
ntls timer show    
package
package deletefile      
package erase    
package list    
package listfile    
package update    
package verify    
partition
partition backup      
partition create    
partition delete    
partition list    
partition rename    
partition resize    
partition restore      
partition show    
service
service list    
service restart      
service start      
service status    
service stop      
status
status cpu    
status date    
status disk    
status handles    
status interface    
status mac    
status mem    
status memmap    
status netstat    
status ps    
status sensors    
status sysstat code    
status sysstat show    
status time    
status zone    
stc
stc activationtimeout set    
stc activationtimeout show  
stc cipher disable    
stc cipher enable    
stc cipher show  
stc hmac disable    
stc hmac enable    
stc hmac show  
stc partition export    
stc partition show  
stc rekeythreshold set    
stc rekeythreshold show  
sysconf
sysconf appliance hardreboot        
sysconf appliance poweroff      
sysconf appliance reboot      
sysconf appliance rebootonpanic disable      
sysconf appliance rebootonpanic enable      
sysconf appliance rebootonpanic show    
sysconf banner add        
sysconf banner clear        
sysconf config backup        
sysconf config clear        
sysconf config delete        
sysconf config export        
sysconf config factoryreset       configurable
sysconf config import        
sysconf config list    
sysconf config restore        
sysconf config show    
sysconf drift init      
sysconf drift reset      
sysconf drift set      
sysconf drift startmeasure      
sysconf drift status    
sysconf drift stopmeasure      
sysconf fingerprint license    
sysconf fingerprint ntls    
sysconf fingerprint ssh    
sysconf forcesologin disable      
sysconf forcesologin enable      
sysconf forcesologin show        
sysconf license apply      
sysconf license list    
sysconf license revoke      
sysconf ntp addserver      
sysconf ntp autokeyauth clear      
sysconf ntp autokeyauth generate      
sysconf ntp autokeyauth install      
sysconf ntp autokeyauth list      
sysconf ntp autokeyauth update      
sysconf ntp deleteserver      
sysconf ntp disable      
sysconf ntp enable      
sysconf ntp listservers    
sysconf ntp log tail      
sysconf ntp ntpdate      
sysconf ntp show    
sysconf ntp status    
sysconf ntp symmetricauth key add      
sysconf ntp symmetricauth key clear      
sysconf ntp symmetricauth key delete      
sysconf ntp symmetricauth key list    
sysconf ntp symmetricauth trustedkeys add      
sysconf ntp symmetricauth trustedkeys clear      
sysconf ntp symmetricauth trustedkeys delete      
sysconf ntp symmetricauth trustedkeys list    
sysconf radius addserver        
sysconf radius deleteserver        
sysconf radius disable        
sysconf radius enable        
sysconf radius show        
sysconf regencert       configurable
sysconf reimage start      
sysconf reimage tarlog        
sysconf snmp disable      
sysconf snmp enable      
sysconf snmp notification add      
sysconf snmp notification clear      
sysconf snmp notification delete      
sysconf snmp notification list    
sysconf snmp show    
sysconf snmp trap clear      
sysconf snmp trap disable      
sysconf snmp trap enable      
sysconf snmp trap set      
sysconf snmp trap show    
sysconf snmp trap test      
sysconf snmp user add      
sysconf snmp user clear      
sysconf snmp user delete      
sysconf snmp user list    
sysconf ssh device      
sysconf ssh ip      
sysconf ssh password disable      
sysconf ssh password enable      
sysconf ssh port        
sysconf ssh publickey disable      
sysconf ssh publickey enable      
sysconf ssh regenkeypair      
sysconf ssh show    
sysconf time      
sysconf timezone list    
sysconf timezone set      
sysconf timezone show    
sysconf tls ciphers reset        
sysconf tls ciphers set        
sysconf tls ciphers show    
syslog
syslog cleanup        
syslog export      
syslog period      
syslog remotehost add      
syslog remotehost clear      
syslog remotehost delete      
syslog remotehost list      
syslog rotate      
syslog rotations      
syslog severity set        
syslog show    
syslog tail    
syslog tarlogs    
token
token backup factoryreset      
token backup init      
token backup list    
token backup login      
token backup logout      
token backup partition delete      
token backup partition list    
token backup partition show    
token backup show    
token backup update capability      
token backup update firmware      
token backup update show    
user
user add        
user delete        
user disable        
user enable        
user list        
user password        
user radiusadd        
user role add        
user role clear
       
user role delete        
user role import        
user role list        
webserver
webserver bind        
webserver certificate generate        
webserver certificate show        
webserver ciphers set        
webserver ciphers show        
webserver disable        
webserver enable        
webserver show