Importing keys
The -import command helps to import keys and keys groups across domains. The following list contains important information about importing keys and key groups:
When importing keys and key groups, you must have the key container file that is created during the export operation. You also need the same pass phrase that is used during the export.
Importing keys is an atomic operation. It reverts backs all updates on encounter of any error during operation.
Partial import is not supported.
A preview of the import output is available. Run the -preview command to preview the results of the import.
The import operation can have two modes, one that includes the -preserve_kgname command and another that excludes the -preserve_kgname command.
By default, the key groups are imported with following name format:
< Original_Kgname_<timestamp> >
You can opt to preserve the key group name by explicitly specifying the <-preserve_kgname> option.
Duplicate keys such as the keys with the same key tag or the same key are not imported.
The import does not support key group merging.
You can however merge the keys, import the key group without using the <-preserve_kgname> command. Run the nbkmsutil -modifykey -keyname <key_name> -kgname <key_group_name> command to move key from current group to the required group.
For more information about moving keys:
If the same key(s) or key(s) that have the same key tags exist in a key group, they are ignored during import. Run the following commands to import the keys and key groups:
# nbkmsutil -import -path <secure_key_container>
[-preserve_kgname]
[ -desc <description> ]
[ -preview ]
The -preserve_kgname command preserves the key group names during import.
The -desc <description> command is a description that is associated with the key groups during import.
The -preview command display a preview of the import results.
Run the import operation with the -preserve_kgname as follows:
nbkmsutil - import -path
<secure_key_container>
[-preserve_kgname]
When you run the -import command with the -preserve_kgname command, the import operation tries to import the original key groups names from the key container. If a key group with the same name exists, the import operation fails.
Run the import operation without the -preserve_kgname as follows:
nbkmsutil - import -path
<secure_key_container>
When you run the -import command without the -preserve_kgname it imports the key groups, but the key group names are renamed using a suffix, for example a timestamp. Each key group that is renamed always has a unique name.