package sys import ( "github.com/versenilvis/iris/spec" ) func init() { spec.Register(&spec.Spec{ Name: "ykman", Description: "Configure your YubiKey via the command line", Subcommands: []spec.Subcommand{ {Name: "list", Description: "List connected YubiKeys"}, {Name: "config", Description: "Enable or disable applications"}, {Name: "mode", Description: "Manage connection modes (USB Interfaces)"}, {Name: "nfc", Description: "Enable or disable applications over NFC"}, {Name: "set-lock-code", Description: "Set or change the configuration lock code"}, {Name: "usb", Description: "Enable or disable applications over USB"}, {Name: "fido", Description: "Manage the FIDO applications"}, {Name: "info", Description: "Display general status of the FIDO2 application"}, {Name: "access", Description: "Manage the PIN for FIDO"}, {Name: "change-pin", Description: "Set or change PIN code"}, {Name: "verify-pin", Description: "Verify the PIN against a YubiKey"}, {Name: "delete", Description: "Delete a credential"}, {Name: "fingerprints", Description: "Manage fingerprints"}, {Name: "add", Description: "Add a new fingerprint"}, {Name: "rename", Description: "Set the label for a fingerprint"}, {Name: "oath", Description: "Manage the OATH applications"}, {Name: "forget", Description: "Remove a stored password from this computer"}, {Name: "accounts", Description: "Manage and use OATH accounts"}, {Name: "NAME", Description: "Human readable name of the account, such as a username or e-mail address"}, {Name: "SECRET", Description: "Base32-encoded secret/key value provided by the server"}, {Name: "code", Description: "Generate codes"}, {Name: "QUERY", Description: "Provide a query string to match one or more specific accounts"}, {Name: "uri", Description: "Add a new account from an otpauth:// URI"}, {Name: "openpgp", Description: "Manage the OpenPGP applications"}, {Name: "reset", Description: "Reset all the OpenPGP data"}, {Name: "set-retries", Description: "Set PIN, Reset Code and Admin PIN retries"}, {Name: "certificates", Description: "Manage certificates"}, {Name: "KEY", Description: "Key slot to delete certificate from (sig, enc, aut, or att)"}, {Name: "export", Description: "Export an OpenPGP certificate"}, {Name: "CERTIFICATE", Description: "File to write certificate to. Use '-' to use stdout"}, {Name: "import", Description: "Import an OpenPGP certificate"}, {Name: "keys", Description: "Manage private keys"}, {Name: "PRIVATE-KEY", Description: "File containing the private key. Use '-' to use stdin"}, {Name: "set-touch", Description: "Set touch policy for OpenPGP key"}, {Name: "POLICY", Description: "Touch policy to set (on, off, fixed, cached or cached-fixed)"}, {Name: "otp", Description: "Manage the YubiOTP applications"}, {Name: "chalresp", Description: "Program a challenge-response operation"}, {Name: "hotp", Description: "Program an HMAC-SHA1 OATH-HOTP credential"}, {Name: "ndef", Description: "Configure a slot to be used over NDEF (NFC)"}, {Name: "settings", Description: "Update the settings for a slot"}, {Name: "static", Description: "Configure a static password"}, {Name: "swap", Description: "Swaps the two slot configurations"}, {Name: "yubiotp", Description: "Program a Yubico OTP credential"}, {Name: "piv", Description: "Manage the PIV applications"}, {Name: "change-management-key", Description: "Change the management key"}, {Name: "change-puk", Description: "Change the PUK code"}, {Name: "unblock-pin", Description: "Unblock the PIN (using PUK)"}, {Name: "SLOT", Description: "PIV slot of the certificate"}, {Name: "generate", Description: "Generate a self-signed X.509 certificate"}, {Name: "PUBLIC-KEY", Description: "File containing a public key. Use '-' to use stdin"}, }, Options: []spec.Option{ {Name: "-c", Description: "Check if YubiKey is in FIPS Approved mode (available on YubiKey 4 FIPS only)"}, {Name: "-h", Description: "Show info usage information"}, {Name: "-s", Description: "List available smart card readers"}, {Name: "--touch-eject", Description: "Confirm the action without prompting"}, {Name: "-f", Description: "Confirm the action without prompting"}, {Name: "-e", Description: "Enable applications"}, {Name: "-d", Description: "Disable applications"}, {Name: "-a", Description: "Enable all applications"}, {Name: "-D", Description: "Disable all applications"}, {Name: "-l", Description: "List enabled applications"}, {Name: "-L", Description: "Current application configuration lock code"}, {Name: "-n", Description: "New lock code. Conflicts with --generate"}, {Name: "-g", Description: "Generate a random lock code. Conflicts with --new-lock-code"}, {Name: "--autoeject-timeout", Description: "Show config usb usage information"}, {Name: "-P", Description: "Current PIN code"}, {Name: "-u", Description: "Set FIDO U2F pin instead of FIDO2 PIN"}, {Name: "-p", Description: "Provide a password to unlock the YubiKey"}, {Name: "-o", Description: "Time-based (TOTP) or counter-based (HOTP) account"}, {Name: "-i", Description: "Issuer of the account"}, {Name: "-t", Description: "Require touch on YubiKey to generate code"}, {Name: "-r", Description: "Remember the password on this machine"}, {Name: "-H", Description: "Include hidden accounts"}, {Name: "-F", Description: "Encoding format"}, {Name: "-T", Description: "Generate a TOTP code, use the current time if challenge is omitted"}, {Name: "--no-enter", Description: "Don't send an Enter keystroke after outputting the code"}, {Name: "--prefix", Description: "Added before the NDEF payload. Typically a URI"}, {Name: "-A", Description: "Remove access code from the slot"}, {Name: "--enter", Description: "Should send 'Enter' keystroke after slot output. (default: enter)"}, {Name: "--use-numeric-keypad", Description: "Show otp settings usage information"}, {Name: "-k", Description: "Keyboard layout to use for the static password"}, {Name: "-S", Description: "Use YubiKey serial number as public ID. Conflicts with --public-id"}, {Name: "-G", Description: "Generate a random secret key. Conflicts with --key"}, {Name: "--access-code", Description: "Show otp usage information"}, {Name: "-m", Description: "Current management key"}, {Name: "-v", Description: "Verify that the certificate matches the private key in the slot"}, {Name: "--pin-policy", Description: "PIN policy for slot"}, {Name: "--touch-policy", Description: "Touch policy for slot"}, {Name: "--log-file", Description: "Show diagnostics information useful for troubleshooting"}, {Name: "--full-help", Description: "Show --help, including hidden commands, and exit"}, }, }) }